CVE-2026-21721: Grafana
High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.
Affected products
- Grafana Grafana: from 10.2.0, before 11.6.9 (fixed in 11.6.9); from 12.0.0, before 12.0.8 (fixed in 12.0.8); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 12.2.0, before 12.2.3 (fixed in 12.2.3); version 11.6.9 only; version 12.0.8 only; …
Published 2026-01-27. Last modified 2026-07-20.