CVE-2026-19197
Aliases:UBUNTU-CVE-2026-19197CGA-47rg-cwmm-vvwqCGA-5q6p-vq25-pmg8CGA-f5j2-xvwm-76mgCGA-mjcx-fx7g-qrgwCGA-x25r-97fq-48qwCGA-x33x-6hg2-qhqv
Advisory lineage Upstream: 0 Downstream: 1
Downstream
Awaiting Analysis
Published: 26 Aug 2026, 08:50
Last modified:27 Aug 2026, 17:22
Vulnerability Summary
Overall Risk (default)
medium
25/100 CVSS Score
6.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.2% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Aug 2026, 08:50
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated
Description
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
CVSS Metrics
- v3.1•MEDIUM•Score: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Trends
Current EPSS score: 0.20%• Percentile: 10%
Techniques & Countermeasures
- CWE-862•Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Affected Systems
- chainguard•percona-grafana
all
- ubuntu•grafana
all
- grafana•grafana enterprise
≥ 12.4.0, < 12.4.8 | ≥ 13.0.0, < 13.0.6 | ≥ 13.1.0, < 13.1.3
- grafana•grafana oss
≥ 12.4.0, < 12.4.8 | ≥ 13.0.0, < 13.0.6 | ≥ 13.1.0, < 13.1.3