Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21721

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 8.1

Описание

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

An authorization error has been discovered in Grafana dashboards. The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Affected
Red Hat Ceph Storage 5rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 5rhel8/grafanaAffected
Red Hat Ceph Storage 5rhel9/grafanaAffected
Red Hat Ceph Storage 6rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 6rhel8/grafanaAffected
Red Hat Ceph Storage 6rhel9/grafanaAffected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 8rhel8/grafanaAffected
Red Hat Ceph Storage 8rhel9/grafanaAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2433242grafana/grafana/pkg/services/dashboards: Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
5 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
nvd
5 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
debian
5 месяцев назад

The dashboard permissions API does not verify the target dashboard sco ...

CVSS3: 8.1
github
5 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
fstec
5 месяцев назад

Уязвимость прикладного программного интерфейса платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

8.1 High

CVSS3