CVE-2026-13720 PUBLISHED

Editor can forge file-provisioning provenance on dashboards via the dashboard API

Assigner: GRAFANA
Reserved: 29.06.2026 Published: 30.09.2026 Updated: 30.09.2026

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 5.4

Product Status

Vendor Grafana
Product Grafana OSS
Versions Default: unaffected
  • affected from 12.0.0 to 12.0.10 (incl.)
  • affected from 12.1.0 to 12.1.10 (incl.)
  • affected from 12.2.0 to 12.2.11 (incl.)
  • affected from 12.3.0 to 12.3.11 (incl.)
  • affected from 12.4.0 to 12.4.12 (excl.)
  • affected from 13.0.0 to 13.0.10 (excl.)
  • affected from 13.1.0 to 13.1.7 (excl.)
  • affected from 13.2.0 to 13.2.3 (excl.)
Vendor Grafana
Product Grafana Enterprise
Versions Default: unaffected
  • affected from 12.0.0 to 12.0.10 (incl.)
  • affected from 12.1.0 to 12.1.10 (incl.)
  • affected from 12.2.0 to 12.2.11 (incl.)
  • affected from 12.3.0 to 12.3.11 (incl.)
  • affected from 12.4.0 to 12.4.12 (excl.)
  • affected from 13.0.0 to 13.0.10 (excl.)
  • affected from 13.1.0 to 13.1.7 (excl.)
  • affected from 13.2.0 to 13.2.3 (excl.)

Credits

  • arang (Researcher) finder

References

Problem Types

  • CWE-285 CWE
  • CWE-915 CWE
  • CWE-345 CWE