Grafana IRM: improper access control
High7.1CVE-2026-9765 · Published Jul 24, 2026 · updated Jul 30, 2026
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana IRM Product | >= 1.0.0, <= 1.164.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Grafana OSS: resource exhaustion | Medium5.3 | No fix yet |
| Jul 16 | Grafana Labs Loki: resource exhaustion | High7.5 | v3.7.0 |
| Jul 15 | Grafana MCP Server: server-side request forgery | High8.6 | No fix yet |
| Jul 10 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |
| Jul 10 | Grafana OSS: denial of service | Medium5.3 | No fix yet |
| Jul 10 | Grafana OSS: resource exhaustion | High7.5 | No fix yet |