Missing Authorization in Grafana Enterprise - CVE-2026-81841

 

Missing Authorization in Grafana Enterprise - CVE-2026-81841

Published: September 30, 2026


Vulnerability identifier: #VU152982
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-81841
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose data source configuration, including stored credentials for data sources using browser access.

The vulnerability exists due to improper authorization in the shared dashboard access-token validation for frontend bootstrap-data endpoints when accessing a paused shared dashboard link. A remote attacker can use the paused dashboard's access token to retrieve the data source configuration without authenticating.

Deleting the shared dashboard revokes the access token.


Affected software

Grafana Enterprise

How to mitigate CVE-2026-81841

Install security update from vendor's website.

Grafana Enterprise - addressed in versions 12.4.12, 13.0.10, 13.1.7, 13.2.3

External References

Related Security Bulletins