Grafana LabsCVE-2026-81841
Grafana: missing authorization
Medium5.3CVE-2026-81841 · Published Sep 29, 2026 · updated Sep 30, 2026
Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana Enterprise Product | >= 11.6.0, <= 11.6.17 | No fix yet |
| >= 12.0.0, <= 12.0.10 | No fix yet | |
| >= 12.1.0, <= 12.1.10 | No fix yet | |
| >= 12.2.0, <= 12.2.11 | No fix yet | |
| Grafana OSS Product | >= 11.6.0, <= 11.6.17 | No fix yet |
| >= 12.0.0, <= 12.0.10 | No fix yet | |
| >= 12.1.0, <= 12.1.10 | No fix yet | |
| >= 12.2.0, <= 12.2.11 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Grafana: improper authorization | Medium5.4 | No fix yet |
| Sep 30 | Grafana: information disclosure | Medium4.3 | 12.4.12+2 more |
| Sep 29 | Grafana: improper authorization | Medium4.3 | 12.4.12+1 more |
| Sep 17 | Grafana: cross-site scripting | High7.3 | No fix yet |
| Sep 17 | Grafana: remote code execution | High8.8 | No fix yet |
| Sep 2 | Grafana OSS: denial of service | Medium6.5 | No fix yet |