Grafana LabsCVE-2026-13720
Grafana: improper authorization
Medium5.4CVE-2026-13720 · Published Sep 30, 2026
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana Enterprise Product | >= 12.0.0, <= 12.0.10 | No fix yet |
| >= 12.1.0, <= 12.1.10 | No fix yet | |
| >= 12.2.0, <= 12.2.11 | No fix yet | |
| >= 12.3.0, <= 12.3.11 | No fix yet | |
| Grafana OSS Product | >= 12.0.0, <= 12.0.10 | No fix yet |
| >= 12.1.0, <= 12.1.10 | No fix yet | |
| >= 12.2.0, <= 12.2.11 | No fix yet | |
| >= 12.3.0, <= 12.3.11 | No fix yet |
Details and references
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Grafana: information disclosure | Medium4.3 | 12.4.12+2 more |
| Sep 29 | Grafana: missing authorization | Medium5.3 | No fix yet |
| Sep 29 | Grafana: improper authorization | Medium4.3 | 12.4.12+1 more |
| Sep 17 | Grafana: cross-site scripting | High7.3 | No fix yet |
| Sep 17 | Grafana: remote code execution | High8.8 | No fix yet |
| Sep 2 | Grafana OSS: denial of service | Medium6.5 | No fix yet |