Broken Access Control in Grafana Affects Multiple Organizations
CVE-2026-19197
6.3MEDIUM
What is CVE-2026-19197?
This vulnerability allows an organization administrator on a Grafana instance to delete dashboard snapshots of other organizations. The attacker can exploit this flaw by retrieving a snapshot's secret delete key using its public share key, thus compromising the integrity of dashboard data across shared environments.
Affected Version(s)
Grafana Enterprise 12.4.0 < 12.4.8
Grafana Enterprise 13.0.0 < 13.0.6
Grafana Enterprise 13.1.0 < 13.1.3