Authorization Bypass in Grafana Affects User Permissions
CVE-2026-72585
6.5MEDIUM
What is CVE-2026-72585?
An authorization bypass vulnerability in Grafana enables an Editor-role user to delete protected contact points without possessing the necessary permissions for alert notifications. This flaw compromises the integrity of alert systems by allowing unprivileged users to alter critical configuration settings.
Affected Version(s)
Grafana 0 <= 13.2.0
