Skip to content
Grafana LabsCVE-2026-81841

Grafana: missing authorization

Medium5.3CVE-2026-81841 · Published Sep 29, 2026 · updated Sep 30, 2026

Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana Enterprise
Product
>= 11.6.0, <= 11.6.17No fix yet
>= 12.0.0, <= 12.0.10No fix yet
>= 12.1.0, <= 12.1.10No fix yet
>= 12.2.0, <= 12.2.11No fix yet
Grafana OSS
Product
>= 11.6.0, <= 11.6.17No fix yet
>= 12.0.0, <= 12.0.10No fix yet
>= 12.1.0, <= 12.1.10No fix yet
>= 12.2.0, <= 12.2.11No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana: improper authorization
Medium5.4Sep 30
Grafana: information disclosure
Medium4.3Sep 30
Grafana: improper authorization
Medium4.3Sep 29
Grafana: cross-site scripting
High7.3Sep 17
Grafana: remote code execution
High8.8Sep 17
Grafana OSS: denial of service
Medium6.5Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.