CVE-2026-21722: Grafana

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

Affected products

  • Grafana Grafana: from 9.3.0, before 11.6.10 (fixed in 11.6.10); from 12.0.0, before 12.1.6 (fixed in 12.1.6); from 12.2.0, up to and including 12.2.4; from 12.3.0, up to and including 12.3.2; version 11.6.10 only; version 12.1.6 only; …

Published 2026-02-12. Last modified 2026-06-17.