CVE-2026-72585 PUBLISHED

Grafana - Incomplete Fix for CVE-2026-21724 Allows Editor Role to Delete Protected Contact Points

Assigner: TuranSec
Reserved: 10.08.2026 Published: 10.08.2026 Updated: 10.08.2026

An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 6.5

Product Status

Vendor Grafana Labs
Product Grafana
Versions Default: unknown
  • affected from 0 to 13.2.0 (incl.)

Credits

  • Eldor Nabijonov finder

References

Problem Types

  • CWE-284: Improper Access Control CWE