Junglewise Threat Intelligence

CVE-2026-33377: Grafana privilege escalation via dashboard overwrite

CVE-2026-33377 · Severity: high · CVSS 7.1 · Published 2026-05-13

Vendors: Grafana Labs.

Executive brief

Grafana is a popular data visualization and monitoring platform used to create dashboards for tracking business and technical metrics. A security flaw allows users with 'Editor' permissions to overwrite dashboards they do not own, effectively granting themselves administrative control over those specific dashboards. This could allow an unauthorized user to modify critical monitoring views or restrict access for legitimate administrators.

Technical details

An improper access control vulnerability (CWE-284/CWE-287) exists in Grafana's dashboard import and overwrite functionality. A user with the 'Editor' role and write access to a specific dashboard can overwrite that dashboard, which results in the Access Control List (ACL) being reset or modified such that the Editor acquires 'Admin' permissions for that dashboard. The attack is network-reachable and requires low-privileged authentication. This allows for local privilege escalation within the context of specific dashboard management. Patches are available in versions 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1 (and subsequent security releases).

Affected products

  • Grafana Labs Grafana 8.5.0 to 11.6.13, 12.2.0 to 12.2.7, 12.3.0 to 12.3.5, 12.4.0 to 12.4.2, 13.0.0

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory
  • 2026-05-13: patched

References