Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28378

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

A flaw in Grafana's public dashboard deletion endpoint lacks organization isolation, allowing an Organization Administrator to delete public dashboards in other organizations using the target dashboard's ID.

Отчет

This Low impact flaw in Grafana allows an authenticated Organization Administrator to delete public dashboards belonging to other organizations. This is due to insufficient isolation enforcement in the public dashboard deletion endpoint, potentially affecting the availability of dashboards in multi-organizational Grafana deployments.

Меры по смягчению последствий

Since this vulnerability only affects the Public Dashboards feature, environments that do not utilize public dashboards can completely neutralize the risk by disabling the feature. This removes the vulnerable endpoint from the attack surface entirely.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Not affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Not affected
Red Hat Ceph Storage 9rhceph/grafana-rhel10Not affected
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2497887grafana: Grafana: Unauthorized public dashboard deletion across organizations

EPSS

Процентиль: 3%
0.00136
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
23 дня назад

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
github
23 дня назад

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

EPSS

Процентиль: 3%
0.00136
Низкий

3.1 Low

CVSS3