Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-72585

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.

An authorization bypass in Grafana allows Editor-role users to delete protected contact points because a previous security patch for updating them missed the deletion process.

Отчет

This Moderate impact authorization bypass in Grafana allows an authenticated Editor-role user to delete protected contact points without the necessary permissions. This could disrupt alert notifications in Red Hat deployments where Grafana is configured with alert managers and Editor-role users have access to manage alert configurations.

Меры по смягчению последствий

To mitigate this issue grant the Editor role only to trusted users and restrict access to the Grafana UI/API to trusted networks. Audit contact-point / receiver deletions and treat protected notification endpoints as sensitive configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Fix deferred
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/grafana-rhel9Not affected
Red Hat Ceph Storage 9rhceph/grafana-rhel10Fix deferred
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2513106grafana: Grafana: Authorization bypass allows Editor to delete protected contact points

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
19 дней назад

An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.

nvd
19 дней назад

Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

CVSS3: 6.5
github
19 дней назад

An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.

6.5 Medium

CVSS3