Cross-Organization Public Dashboard Deletion via Missing Org Isolation

Low
Advisory ID:CVE-2026-28378
Published:2026-03-24
Product:Grafana
CVSS Score:3.1
CVSS Vector:CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Fixed Versions:
>=11.6.14
>=12.1.10
>=12.2.8
>=12.3.6
>=12.4.2
>=13.0.0

Summary

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard’s identifiers.