SB2026093090 - Multiple vulnerabilities in Grafana Enterprise



SB2026093090 - Multiple vulnerabilities in Grafana Enterprise

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093090
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Missing Authorization (CVE-ID: CVE-2026-81842)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to move library panels into folders where they have only view permission.

The vulnerability exists due to improper authorization in the library panel update path when moving a library panel to a destination folder through the library elements API or equivalent App Platform resource. A remote user can submit a library panel move to a folder without library panel create permission to move library panels into folders where they have only view permission.

No data from the destination folder is disclosed, and existing content there cannot be changed.


2) Missing Authorization (CVE-ID: CVE-2026-81841)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose data source configuration, including stored credentials for data sources using browser access.

The vulnerability exists due to improper authorization in the shared dashboard access-token validation for frontend bootstrap-data endpoints when accessing a paused shared dashboard link. A remote attacker can use the paused dashboard's access token to retrieve the data source configuration without authenticating.

Deleting the shared dashboard revokes the access token.


Remediation

Install update from vendor's website.