Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21721

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

An authorization error has been discovered in Grafana dashboards. The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Ceph Storage 5rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 5rhel8/grafanaAffected
Red Hat Ceph Storage 5rhel9/grafanaAffected
Red Hat Ceph Storage 6rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 6rhel8/grafanaAffected
Red Hat Ceph Storage 6rhel9/grafanaAffected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 8rhel8/grafanaAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2433242grafana/grafana/pkg/services/dashboards: Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation

EPSS

Процентиль: 1%
0.00011
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
nvd
около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
debian
около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard sco ...

CVSS3: 8.1
github
около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
fstec
около 2 месяцев назад

Уязвимость прикладного программного интерфейса платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 1%
0.00011
Низкий

8.1 High

CVSS3