CVE-2026-21724 PUBLISHED

Missing Protected-field Authorization in Provisioning Contact Points API

Assigner: GRAFANA
Reserved: 05.01.2026 Published: 26.03.2026 Updated: 27.03.2026

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor Grafana
Product Grafana OSS
Versions Default: unaffected
  • affected from 12.3.1 to 12.3.6 (excl.)
  • affected from 12.2.2 to 12.2.8 (excl.)
  • affected from 12.1.5 to 12.1.10 (excl.)
  • affected from 11.6.9 to 11.6.14 (excl.)

References