Broken access control in dashboard snapshots

Medium
Advisory ID:CVE-2026-19197
Published:2026-08-26
Product:Grafana OSS
CVSS Score:6.3
CVSS Vector:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Fixed Versions:
<12.4.0
>=12.4.8 <13.0.0
>=13.0.6 <13.1.0
>=13.1.3

Summary

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot’s secret delete key using only its public share key (broken access control).