Improper access control in Grafana - CVE-2026-33381
Published: May 18, 2026
Grafana
Detailed vulnerability description
The vulnerability allows a remote user to generate service account tokens after permissions removal.
The vulnerability exists due to improper access control in service account token generation when permission revocation is being processed. A remote privileged user can generate a service account token during the brief window after access is revoked to generate service account tokens after permissions removal.
Access may remain usable for a few seconds after the revocation event before it is fully removed.