Junglewise Threat Intelligence

CVE-2026-19197: Grafana OSS broken access control in dashboard snapshots

CVE-2026-19197 · Severity: medium · CVSS 6.3 · Published 2026-08-26

Vendors: Grafana.

Executive brief

Grafana is an observability and monitoring platform widely used to visualize operational data and dashboards. An administrator within one organization can delete snapshots (saved dashboard views) belonging to other organizations and can recover a snapshot's secret deletion key from its public share link, allowing unauthorized access and deletion of sensitive dashboard records across organizational boundaries.

Technical details

This vulnerability is a broken access control issue affecting Grafana dashboard snapshot functionality. A user with organization administrator permissions can exploit insufficient authorization checks to delete snapshots from other organizations on the same instance and derive the secret delete key from the public share key. The attack requires network access to the Grafana instance and valid organization administrator credentials (authentication required). An authenticated attacker can delete snapshots and gain write access to snapshot resources outside their organization. Patches are available in Grafana OSS versions 12.4.8, 13.0.6, and 13.1.3 or later.

Affected products

  • Grafana Grafana OSS before 12.4.8, 13.0.0 before 13.0.6, 13.1.0 before 13.1.3

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Fixed in versions 12.4.8, 13.0.6, 13.1.3 and later

References