CVE-2026-21724: Grafana

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

Affected products

  • Grafana Grafana: from 11.6.9, before 11.6.14 (fixed in 11.6.14); from 12.1.5, before 12.1.10 (fixed in 12.1.10); from 12.2.2, before 12.2.8 (fixed in 12.2.8); from 12.3.1, before 12.3.6 (fixed in 12.3.6)

Published 2026-03-26. Last modified 2026-06-17.