Grafana LabsCVE-2026-28378
Grafana: improper access control
Low3.1CVE-2026-28378 · Published Jul 7, 2026 · updated Jul 10, 2026
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana Enterprise Product | >= 11.6.0, <= 11.6.13 | No fix yet |
| >= 12.1.0, <= 12.1.9 | No fix yet | |
| >= 12.2.0, <= 12.2.7 | No fix yet | |
| >= 12.3.0, <= 12.3.5 | No fix yet | |
| Grafana OSS Product | >= 11.6.0, <= 11.6.13 | No fix yet |
| >= 12.1.0, <= 12.1.9 | No fix yet | |
| >= 12.2.0, <= 12.2.7 | No fix yet | |
| >= 12.3.0, <= 12.3.5 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Grafana OSS: resource exhaustion | Medium5.3 | No fix yet |
| Jul 16 | Grafana Labs Loki: resource exhaustion | High7.5 | v3.7.0 |
| Jul 15 | Grafana MCP Server: server-side request forgery | High8.6 | No fix yet |
| Jul 10 | Grafana OSS: denial of service | Medium5.3 | No fix yet |
| Jul 10 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |
| Jul 10 | Grafana OSS: resource exhaustion | High7.5 | No fix yet |