Improper access control in Grafana - CVE-2026-33377
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges on a specific dashboard.
The vulnerability exists due to improper access control in the dashboard import functionality when importing a dashboard with write access to an existing dashboard. A remote user can overwrite a dashboard not owned by them to escalate privileges on that specific dashboard.
The user must have write access to the dashboard to exploit this issue.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Aruba Networking Private 5G Core
grafana (Red Hat package)
grafana
grafana-selinux
How to mitigate CVE-2026-33377
Aruba Networking Private 5G Core - update to 1.26.1.3
grafana (Red Hat package) - addressed in versions 9.2.10-32.el8_10.1, 10.2.6-28.el10_2.4
grafana - update to 9.2.10-32.0.1
grafana-selinux - update to 9.2.10-32.0.1