Improper access control in Grafana - CVE-2026-33377
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges on a specific dashboard.
The vulnerability exists due to improper access control in the dashboard import functionality when importing a dashboard with write access to an existing dashboard. A remote user can overwrite a dashboard not owned by them to escalate privileges on that specific dashboard.
The user must have write access to the dashboard to exploit this issue.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
grafana (Red Hat package)
grafana
grafana-selinux
Aruba Networking Private 5G Core
How to mitigate CVE-2026-33377
Aruba Networking Private 5G Core - update to 1.26.1.3
grafana (Red Hat package) - addressed in versions 9.2.10-32.el8_10.1, 10.2.6-23.el9_6, 10.2.6-23.el9_8.2, 10.2.6-28.el10_2.4
grafana - update to 9.2.10-32.0.1
grafana-selinux - update to 9.2.10-32.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Grafana
- Red Hat Enterprise Linux 10 update for grafana
- Multiple vulnerabilities in HPE Aruba Networking Private 5G Core
- Red Hat Enterprise Linux 8 update for grafana
- Anolis OS update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9 update for grafana