CVE-2025-3260
A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources.
EPSS 0.01% · 0.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 11.6.0 |
| Bitnami | grafana | 11.6.0 |
Exploit Intelligence
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
- CVE-2025-3260.json (github-poc)
…and 10 more exploits
Timeline
- Apr 22, 2025 CVE Published
- Jun 2, 2025 EPSS Score
- Jun 7, 2025 Coalition ESS Score
- Jun 13, 2025 EPSS Score
- Jun 24, 2025 EPSS Score
- Jul 4, 2025 EPSS Score
- Jul 15, 2025 EPSS Score
- Jul 26, 2025 EPSS Score
- Aug 6, 2025 EPSS Score
- Aug 16, 2025 EPSS Score
- Aug 22, 2025 Coalition ESS Score
- Aug 26, 2025 Coalition ESS Score