VDB

CVE-2025-3260

CVE-2025-3260 PUBLISHED

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources.

EPSS 0.01% · 0.8th percentile

Risk Scores

EPSS Score
0.01%
0.8th percentile

Affected Products

VendorProductVersions
Bitnamigrafana11.6.0
Bitnamigrafana11.6.0

Exploit Intelligence

…and 10 more exploits

Timeline

  • Apr 22, 2025 CVE Published
  • Jun 2, 2025 EPSS Score
  • Jun 7, 2025 Coalition ESS Score
  • Jun 13, 2025 EPSS Score
  • Jun 24, 2025 EPSS Score
  • Jul 4, 2025 EPSS Score
  • Jul 15, 2025 EPSS Score
  • Jul 26, 2025 EPSS Score
  • Aug 6, 2025 EPSS Score
  • Aug 16, 2025 EPSS Score
  • Aug 22, 2025 Coalition ESS Score
  • Aug 26, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›