SB2026100190 - Multiple vulnerabilities in Grafana
Published: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Missing Authorization (CVE-ID: CVE-2026-13720)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to missing authorization in the dashboard API when creating dashboards through the API. A remote user can set file-provisioning metadata to cause a denial of service.
The impact is limited to the same organization.
2) Missing Authorization (CVE-ID: CVE-2026-13719)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose alert rule configuration.
The vulnerability exists due to improper authorization in the alert rules API list endpoint when the set of folders the user may read is empty. A remote user can request alert rules through the list endpoint to disclose alert rule configuration.
Data source credentials are not exposed.
Remediation
Install update from vendor's website.