Cross-Organization Information Disclosure in Grafana Stacks by Grafana Labs
CVE-2026-11817

5.3MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
17 August 2026

What is CVE-2026-11817?

In multi-organization configured Grafana stacks, a vulnerability allows Org Admins of one organization to access permission data of users in other organizations. Specifically, this vulnerability enables the unauthorized retrieval of dashboard and folder identifiers (UIDs) and per-user permissions for dashboards, which could lead to potential misuse of organizational access controls. Notably, sensitive data such as dashboard contents, panels, query results, and personal data remain protected. This issue exclusively affects Grafana businesses utilizing multi-organization settings.

Affected Version(s)

Grafana Enterprise 13.0.0 <= 13.0.3

Grafana Enterprise 12.2.0 <= 12.2.10

Grafana Enterprise 11.2.0 <= 11.6.16

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.