CVE-2026-19197 PUBLISHED

Broken access control in dashboard snapshots

Assigner: GRAFANA
Reserved: 06.08.2026 Published: 26.08.2026 Updated: 26.08.2026

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 6.3

Product Status

Vendor Grafana
Product Grafana OSS
Versions Default: unaffected
  • affected from 12.4.0 to 12.4.8 (excl.)
  • affected from 13.0.0 to 13.0.6 (excl.)
  • affected from 13.1.0 to 13.1.3 (excl.)
Vendor Grafana
Product Grafana Enterprise
Versions Default: unaffected
  • affected from 12.4.0 to 12.4.8 (excl.)
  • affected from 13.0.0 to 13.0.6 (excl.)
  • affected from 13.1.0 to 13.1.3 (excl.)

Credits

  • Snyk finder

References

Problem Types

  • CWE-862 CWE