Broken Access Control in Grafana Affects Multiple Organizations
CVE-2026-19197

6.3MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
26 August 2026

What is CVE-2026-19197?

This vulnerability allows an organization administrator on a Grafana instance to delete dashboard snapshots of other organizations. The attacker can exploit this flaw by retrieving a snapshot's secret delete key using its public share key, thus compromising the integrity of dashboard data across shared environments.

Affected Version(s)

Grafana Enterprise 12.4.0 < 12.4.8

Grafana Enterprise 13.0.0 < 13.0.6

Grafana Enterprise 13.1.0 < 13.1.3

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Snyk
.