Junglewise Threat Intelligence

CVE-2026-21721: Grafana privilege escalation in dashboard permissions API

CVE-2026-21721 · Severity: high · CVSS 8.1 · Published 2026-01-27

Technologies: Red Hat Enterprise Linux AppStream. Vendors: Red Hat, Grafana Labs.

Executive brief

Grafana, a popular data visualization and monitoring platform, contains a security flaw in how it manages dashboard permissions. An internal user who has been granted permission to manage just one specific dashboard can exploit this bug to view or modify the permissions of any other dashboard in the organization. This could lead to unauthorized access to sensitive operational data or the accidental exposure of private monitoring information to the wrong users.

Technical details

An authorization bypass vulnerability (CWE-639/CWE-863) exists in the Grafana dashboard permissions API. The root cause is that the API only checks for the general 'dashboards.permissions:*' action without verifying if the user has authority over the specific target dashboard ID being modified. A remote authenticated attacker with low privileges (specifically, permission management rights on at least one dashboard) can send crafted API requests to read or modify the access control lists (ACLs) of any other dashboard. This results in an organization-internal privilege escalation. Patches have been released by Grafana Labs and downstream vendors like Red Hat.

Affected products

  • Grafana Labs Grafana >=12.3.0 <12.3.1+security-01, >=12.2.0 <12.2.3+security-01, >=12.1.0 <12.1.5+security-01, >=12.0.0 <12.0.8+security-01, >=10.2.0 <11.6.9+security-01
  • Red Hat Red Hat Enterprise Linux AppStream 9, 10
  • Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.12, 2.13
  • Red Hat Red Hat Ceph Storage 5, 6, 8

Timeline

  • 2026-01-27: disclosed: Vulnerability reported via bug bounty program and published by Grafana Labs
  • 2026-01-27: advisory
  • 2026-02-18: patched: Red Hat released security updates for RHEL 9 and 10

References

Related threats