BIT-grafana-2026-21721

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-21721.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2026-21721
Aliases
  • CVE-2026-21721
Published
2026-02-20T08:41:27.652Z
Modified
2026-03-02T09:27:28.879110Z
Summary
Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation
Details

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

Database specific
{
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
10.2.0
Fixed
11.6.9
Introduced
12.0.0
Fixed
12.0.8
Introduced
12.1.0
Fixed
12.1.5
Introduced
12.2.0
Fixed
12.2.3
Introduced
12.3.0
Fixed
12.3.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-21721.json"