Missing Authorization in Grafana Enterprise - CVE-2026-81842
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to move library panels into folders where they have only view permission.
The vulnerability exists due to improper authorization in the library panel update path when moving a library panel to a destination folder through the library elements API or equivalent App Platform resource. A remote user can submit a library panel move to a folder without library panel create permission to move library panels into folders where they have only view permission.
No data from the destination folder is disclosed, and existing content there cannot be changed.