Cross-Organization Information Disclosure in Grafana Stacks by Grafana Labs
CVE-2026-11817
5.3MEDIUM
What is CVE-2026-11817?
In multi-organization configured Grafana stacks, a vulnerability allows Org Admins of one organization to access permission data of users in other organizations. Specifically, this vulnerability enables the unauthorized retrieval of dashboard and folder identifiers (UIDs) and per-user permissions for dashboards, which could lead to potential misuse of organizational access controls. Notably, sensitive data such as dashboard contents, panels, query results, and personal data remain protected. This issue exclusively affects Grafana businesses utilizing multi-organization settings.
Affected Version(s)
Grafana Enterprise 13.0.0 <= 13.0.3
Grafana Enterprise 12.2.0 <= 12.2.10
Grafana Enterprise 11.2.0 <= 11.6.16