Missing Authorization in Grafana Enterprise - CVE-2026-81841
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose data source configuration, including stored credentials for data sources using browser access.
The vulnerability exists due to improper authorization in the shared dashboard access-token validation for frontend bootstrap-data endpoints when accessing a paused shared dashboard link. A remote attacker can use the paused dashboard's access token to retrieve the data source configuration without authenticating.
Deleting the shared dashboard revokes the access token.