CVE-2026-19197: Grafana Enterprise

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).

Affected products

  • Grafana Grafana Enterprise: from 12.4.0, before 12.4.8 (fixed in 12.4.8); from 13.0.0, before 13.0.6 (fixed in 13.0.6); from 13.1.0, before 13.1.3 (fixed in 13.1.3)
  • Grafana Grafana OSS: from 12.4.0, before 12.4.8 (fixed in 12.4.8); from 13.0.0, before 13.0.6 (fixed in 13.0.6); from 13.1.0, before 13.1.3 (fixed in 13.1.3)

Published 2026-08-26. Last modified 2026-08-31.