BIT-grafana-2026-33381

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33381.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2026-33381
Aliases
  • CVE-2026-33381
Published
2026-05-15T08:42:50.824Z
Modified
2026-05-15T11:00:11.433538Z
Summary
Users can generate Service Account tokens after permissions removal
Details

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

Database specific
{
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:go:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
9.2.0
Fixed
11.6.14
Introduced
12.0.0
Fixed
12.2.8
Introduced
12.3.0
Fixed
12.3.6
Introduced
12.4.0
Fixed
12.4.3
Introduced
13.0.0
Fixed
13.0.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33381.json"