Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33377

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

A flaw was found in Grafana. A user with editor privileges can overwrite a dashboard not owned by them, leading to privilege escalation on that specific dashboard. This allows the editor to gain administrative control over the affected dashboard.

Отчет

A privilege escalation flaw exists in Grafana, allowing an authenticated editor with write access to a dashboard to overwrite other dashboards not owned by them. This grants the editor administrative control over the targeted dashboard, potentially leading to unauthorized data manipulation or exposure within the Grafana environment. Red Hat's default deployment does not grant edit access to normal users. Hence, this is rated moderate.

Меры по смягчению последствий

Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 9rhceph/grafana-rhel10Fix deferred
Red Hat Enterprise Linux 10grafanaAffected
Red Hat Enterprise Linux 8grafanaAffected
Red Hat Enterprise Linux 9grafanaAffected
Multicluster Global Hub 1.6.2multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:4462223.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-267
https://bugzilla.redhat.com/show_bug.cgi?id=2477246grafana: Grafana: Privilege escalation via dashboard overwrite

EPSS

Процентиль: 13%
0.00226
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
nvd
3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
debian
3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin ...

CVSS3: 7.1
github
3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
fstec
3 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с перезаписью списков контроля доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 13%
0.00226
Низкий

7.1 High

CVSS3