Skip to content
Grafana LabsCVE-2026-81842

Grafana: improper authorization

Medium4.3CVE-2026-81842 · Published Sep 29, 2026 · updated Sep 30, 2026

An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana Enterprise
Product
>= 12.1.0, <= 12.1.10No fix yet
>= 12.2.0, <= 12.2.11No fix yet
>= 12.3.0, <= 12.3.11No fix yet
>= 12.4.0, < 12.4.1212.4.12
Grafana OSS
Product
>= 12.1.0, <= 12.1.10No fix yet
>= 12.2.0, <= 12.2.11No fix yet
>= 12.3.0, <= 12.3.11No fix yet
>= 12.4.0, < 12.4.1212.4.12
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana: improper authorization
Medium5.4Sep 30
Grafana: information disclosure
Medium4.3Sep 30
Grafana: missing authorization
Medium5.3Sep 29
Grafana: cross-site scripting
High7.3Sep 17
Grafana: remote code execution
High8.8Sep 17
Grafana OSS: denial of service
Medium6.5Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.