CVE-2026-28378: Grafana
Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Affected products
- Grafana Grafana: from 11.6.0, up to and including 11.6.13; from 12.1.0, up to and including 12.1.9; from 12.2.0, up to and including 12.2.7; from 12.3.0, up to and including 12.3.5; version 12.4.0 only
Published 2026-07-07. Last modified 2026-07-10.