Логотип exploitDog
bind: "CVE-2026-21721"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2026-21721"

Количество 11

Количество 11

ubuntu логотип

CVE-2026-21721

около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-21721

около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-21721

около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-21721

около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard sco ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-jgfq-mgxg-4qwm

около 2 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2026-01120

около 2 месяцев назад

Уязвимость прикладного программного интерфейса платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260311-73-0010

16 дней назад

Уязвимость grafana

CVSS3: 8.1
EPSS: Низкий
rocky логотип

RLSA-2026:2920

30 дней назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2026:2914

30 дней назад

Important: grafana security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2920

около 1 месяца назад

ELSA-2026-2920: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2914

около 1 месяца назад

ELSA-2026-2914: grafana security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard sco ...

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-jgfq-mgxg-4qwm

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-01120

Уязвимость прикладного программного интерфейса платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260311-73-0010

Уязвимость grafana

CVSS3: 8.1
0%
Низкий
16 дней назад
rocky логотип
RLSA-2026:2920

Important: grafana security update

30 дней назад
rocky логотип
RLSA-2026:2914

Important: grafana security update

30 дней назад
oracle-oval логотип
ELSA-2026-2920

ELSA-2026-2920: grafana security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-2914

ELSA-2026-2914: grafana security update (IMPORTANT)

около 1 месяца назад

Уязвимостей на страницу