CVE-2025-3260: Grafana
High severity, CVSS 8.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources.
Affected products
- Grafana Grafana: from 11.6.0, before 11.6.1+security-01 (fixed in 11.6.1+security-01)
Published 2025-06-02. Last modified 2026-06-17.