Access Control Vulnerability in Grafana
CVE-2026-28380

6.5MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
13 May 2026

What is CVE-2026-28380?

An access control vulnerability has been identified in Grafana, allowing any user with Editor privileges to delete snapshots, regardless of their permissions to view or modify them. This flaw can lead to significant data loss if sensitive snapshots are removed without authorization. Users are encouraged to review their access controls and apply the latest security updates to mitigate this risk.

Affected Version(s)

Grafana OSS OnPrem 9.4.0 <= 11.6.14

Grafana OSS OnPrem 11.6.14 < 11.6.14+security-04

Grafana OSS OnPrem 12.0.0 <= 12.2.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.