Логотип exploitDog
bind:CVE-2026-22640
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22640

Количество 3

Количество 3

nvd логотип

CVE-2026-22640

25 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-q3c7-4hv8-jhvp

25 дней назад

An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either: - Not part of any organization, or - Part of the same organization as the Organization administrator Impact: - Organization administrators can permanently delete Server administrator accounts - If the only Server administrator is deleted, the Grafana instance becomes unmanageable - No super-user permissions remain in the system - Affects all users, organizations, and teams managed in the instance The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2026-00580

25 дней назад

Уязвимость средства регистрации посылок и отправлений Incoming Goods Suite, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22640

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

25 дней назад
github логотип
GHSA-q3c7-4hv8-jhvp

An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either: - Not part of any organization, or - Part of the same organization as the Organization administrator Impact: - Organization administrators can permanently delete Server administrator accounts - If the only Server administrator is deleted, the Grafana instance becomes unmanageable - No super-user permissions remain in the system - Affects all users, organizations, and teams managed in the instance The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.

CVSS3: 5.5
25 дней назад
fstec логотип
BDU:2026-00580

Уязвимость средства регистрации посылок и отправлений Incoming Goods Suite, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 5.5
25 дней назад

Уязвимостей на страницу