Authorization Bypass in Grafana OSS Affects Users Modifying Webhook URLs
CVE-2026-21724
5.4MEDIUM
What is CVE-2026-21724?
A vulnerability exists in Grafana OSS that allows users with the Editor role to bypass authorization controls. Specifically, this flaw in the provisioning contact points API permits unauthorized modification of protected webhook URLs, even when the user lacks the necessary permissions to do so. This may lead to potential misuse of webhook functions, emphasizing the need for stringent access controls and proper permission checks within the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Grafana OSS OnPrem 12.3.1 < 12.3.6
Grafana OSS OnPrem 12.2.2 < 12.2.8
Grafana OSS OnPrem 12.1.5 < 12.1.10