VDB

CVE-2026-19197

CVE-2026-19197 PUBLISHED CVSS 6.3 MEDIUM

Reported by GRAFANA · Published August 26, 2026

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).

Risk Scores

CVSS 3.1
6.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersions
GrafanaGrafana OSS12.4.0, 13.0.0, 13.1.0
GrafanaGrafana Enterprise12.4.0, 13.0.0, 13.1.0
GrafanaGrafana OSS12.4.0, 13.0.0, 13.1.0
GrafanaGrafana Enterprise12.4.0, 13.0.0, 13.1.0

Timeline

  • Aug 26, 2026 EPSS Score
  • Aug 26, 2026 Coalition ESS Score
  • Aug 26, 2026 CVE Published
  • Aug 27, 2026 CVE Updated
  • Sep 2, 2026 Security Advisory
  • Sep 9, 2026 EPSS Score
  • Sep 15, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›