Privilege Escalation Vulnerability in Grafana Dashboard Permissions
CVE-2026-21721
8.1HIGH
Key Information:
- Vendor
Grafana
- Vendor
- CVE Published:
- 27 January 2026
What is CVE-2026-21721?
The Grafana dashboard permissions API contains a privilege escalation flaw that fails to validate the scope of target dashboards. This oversight allows users with permission management rights on one dashboard to inadvertently access and alter permissions of other dashboards, potentially compromising internal organizational controls and data integrity.
Affected Version(s)
grafana/grafana 12.3.0 < 12.3.1
grafana/grafana 12.2.0 < 12.2.3
grafana/grafana 12.1.0 < 12.1.5