Skip to content
Grafana LabsCVE-2026-13720

Grafana: improper authorization

Medium5.4CVE-2026-13720 · Published Sep 30, 2026

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana Enterprise
Product
>= 12.0.0, <= 12.0.10No fix yet
>= 12.1.0, <= 12.1.10No fix yet
>= 12.2.0, <= 12.2.11No fix yet
>= 12.3.0, <= 12.3.11No fix yet
Grafana OSS
Product
>= 12.0.0, <= 12.0.10No fix yet
>= 12.1.0, <= 12.1.10No fix yet
>= 12.2.0, <= 12.2.11No fix yet
>= 12.3.0, <= 12.3.11No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-285, CWE-345, CWE-915

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana: information disclosure
Medium4.3Sep 30
Grafana: missing authorization
Medium5.3Sep 29
Grafana: improper authorization
Medium4.3Sep 29
Grafana: cross-site scripting
High7.3Sep 17
Grafana: remote code execution
High8.8Sep 17
Grafana OSS: denial of service
Medium6.5Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.