Missing Authorization in Grafana Enterprise - CVE-2026-81842

 

Missing Authorization in Grafana Enterprise - CVE-2026-81842

Published: September 30, 2026


Vulnerability identifier: #VU152981
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-81842
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to move library panels into folders where they have only view permission.

The vulnerability exists due to improper authorization in the library panel update path when moving a library panel to a destination folder through the library elements API or equivalent App Platform resource. A remote user can submit a library panel move to a folder without library panel create permission to move library panels into folders where they have only view permission.

No data from the destination folder is disclosed, and existing content there cannot be changed.


Affected software

Grafana Enterprise

How to mitigate CVE-2026-81842

Install security update from vendor's website.

Grafana Enterprise - addressed in versions 12.4.12, 13.0.10

External References

Related Security Bulletins