SB2026100190 - Multiple vulnerabilities in Grafana



SB2026100190 - Multiple vulnerabilities in Grafana

Published: October 1, 2026

Security Bulletin ID SB2026100190
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Missing Authorization (CVE-ID: CVE-2026-13720)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to missing authorization in the dashboard API when creating dashboards through the API. A remote user can set file-provisioning metadata to cause a denial of service.

The impact is limited to the same organization.


2) Missing Authorization (CVE-ID: CVE-2026-13719)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose alert rule configuration.

The vulnerability exists due to improper authorization in the alert rules API list endpoint when the set of folders the user may read is empty. A remote user can request alert rules through the list endpoint to disclose alert rule configuration.

Data source credentials are not exposed.


Remediation

Install update from vendor's website.