Executive brief
A security flaw was identified in Grafana IRM, a tool used by organizations to manage and respond to IT incidents. The vulnerability allows an authenticated user to bypass security rules and access or modify resources they should not be able to reach. This could lead to unauthorized changes to incident data or the takeover of other user accounts within the platform.
Technical details
A broken access control vulnerability exists in Grafana IRM versions 1.0.0 through 1.164.0. The flaw allows a network-based attacker with low-level authenticated privileges to bypass authorization mechanisms. By exploiting this, an attacker can perform operations on behalf of other users, potentially leading to privilege escalation or account takeover. Although originally assigned a CVE, the vendor has noted this is a cloud-only issue, suggesting the fix is managed within the Grafana Cloud environment.
Affected products
- Grafana Labs Grafana IRM 1.0.0 to 1.164.0
Timeline
- 2026-07-24: disclosed: Initial publication of the vulnerability details.
- 2026-07-24: advisory: NVD record published based on Grafana Labs data.