CVE-2026-11817: Grafana Enterprise
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
Affected products
- Grafana Grafana Enterprise: from 13.0.0, up to and including 13.0.3; from 12.2.0, up to and including 12.2.10; from 11.2.0, up to and including 11.6.16; from 12.3.0, up to and including 12.3.8; from 12.4.0, up to and including 12.4.5; from 13.1.0, up to and including 13.1.0
- Grafana Grafana OSS: from 12.4.0, up to and including 12.4.5; from 11.2.0, up to and including 11.6.16; from 13.0.0, up to and including 13.0.3; from 13.1.0, up to and including 13.1.0; from 12.2.0, up to and including 12.2.10; from 12.3.0, up to and including 12.3.8
Published 2026-08-17. Last modified 2026-08-31.