Grafana LabsCVE-2026-81842
Grafana: improper authorization
Medium4.3CVE-2026-81842 · Published Sep 29, 2026 · updated Sep 30, 2026
An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana Enterprise Product | >= 12.1.0, <= 12.1.10 | No fix yet |
| >= 12.2.0, <= 12.2.11 | No fix yet | |
| >= 12.3.0, <= 12.3.11 | No fix yet | |
| >= 12.4.0, < 12.4.12 | 12.4.12 | |
| Grafana OSS Product | >= 12.1.0, <= 12.1.10 | No fix yet |
| >= 12.2.0, <= 12.2.11 | No fix yet | |
| >= 12.3.0, <= 12.3.11 | No fix yet | |
| >= 12.4.0, < 12.4.12 | 12.4.12 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Grafana: improper authorization | Medium5.4 | No fix yet |
| Sep 30 | Grafana: information disclosure | Medium4.3 | 12.4.12+2 more |
| Sep 29 | Grafana: missing authorization | Medium5.3 | No fix yet |
| Sep 17 | Grafana: cross-site scripting | High7.3 | No fix yet |
| Sep 17 | Grafana: remote code execution | High8.8 | No fix yet |
| Sep 2 | Grafana OSS: denial of service | Medium6.5 | No fix yet |