Количество 3
Количество 3
CVE-2026-22640
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
GHSA-q3c7-4hv8-jhvp
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either: - Not part of any organization, or - Part of the same organization as the Organization administrator Impact: - Organization administrators can permanently delete Server administrator accounts - If the only Server administrator is deleted, the Grafana instance becomes unmanageable - No super-user permissions remain in the system - Affects all users, organizations, and teams managed in the instance The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.
BDU:2026-00580
Уязвимость средства регистрации посылок и отправлений Incoming Goods Suite, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-22640 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 25 дней назад | |||
GHSA-q3c7-4hv8-jhvp An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either: - Not part of any organization, or - Part of the same organization as the Organization administrator Impact: - Organization administrators can permanently delete Server administrator accounts - If the only Server administrator is deleted, the Grafana instance becomes unmanageable - No super-user permissions remain in the system - Affects all users, organizations, and teams managed in the instance The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance. | CVSS3: 5.5 | 25 дней назад | ||
BDU:2026-00580 Уязвимость средства регистрации посылок и отправлений Incoming Goods Suite, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации | CVSS3: 5.5 | 25 дней назад |
Уязвимостей на страницу