Broken Access Control Vulnerability in Grafana Cloud Services
CVE-2026-9765

7.1HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
24 July 2026

What is CVE-2026-9765?

Grafana Cloud Services have a broken access control vulnerability that allows unauthorized users to bypass access restrictions, potentially leading to unauthorized data access and account compromises. This flaw could enable attackers to perform actions reserved for higher-privileged users, conduct privilege escalation, or take over accounts entirely. As organizations increasingly rely on cloud services, addressing these vulnerabilities is critical to maintaining data integrity and security.

Affected Version(s)

Grafana IRM 1.0.0 <= 1.164.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.