CVE-2026-21721
Grafana grafana/grafana, grafana/grafana-enterprise, Red Hat Enterprise Linux 10
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.
- CVSS
- 8.1
- EPSS
- 0.65% 47.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.27