Junglewise Threat Intelligence

CVE-2026-28380: Grafana broken access control in Snapshot API

CVE-2026-28380 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Vendors: Grafana Labs.

Executive brief

A security flaw in Grafana allows users with 'Editor' privileges to delete dashboard snapshots they do not own and are not authorized to access. Grafana is a popular platform used for monitoring and visualizing data through dashboards. If exploited, an internal user could cause data loss or disrupt operations by deleting critical historical snapshots used for reporting and troubleshooting.

Technical details

A broken access control (BAC) vulnerability exists in the Grafana Snapshot API due to missing authorization checks (CWE-862). An authenticated attacker with 'Editor' role permissions can send unauthorized requests to delete dashboard snapshots, even if they lack the specific read or write permissions for those snapshots. The vulnerability is reachable over the network and does not require user interaction. Patches are available in versions 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1 (and their respective security releases).

Affected products

  • Grafana Labs Grafana 8.5.0 to 11.6.13, 12.2.0 to 12.2.7, 12.3.0 to 12.3.5, 12.4.0 to 12.4.2, 13.0.0

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory
  • 2026-05-13: patched

References