CVE-2026-19197

Aliases:UBUNTU-CVE-2026-19197CGA-47rg-cwmm-vvwqCGA-5q6p-vq25-pmg8CGA-f5j2-xvwm-76mgCGA-mjcx-fx7g-qrgwCGA-x25r-97fq-48qwCGA-x33x-6hg2-qhqv
Advisory lineage Upstream: 0 Downstream: 1
Awaiting Analysis
Published: 26 Aug 2026, 08:50
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.2% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Aug 2026, 08:50
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).

CVSS Metrics

  • v3.1MEDIUMScore: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

EPSS Trends

Current EPSS score: 0.20% Percentile: 10%

Techniques & Countermeasures

  • CWE-862Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Affected Systems

  • chainguardpercona-grafana

    all

  • ubuntugrafana

    all

  • grafanagrafana enterprise

    ≥ 12.4.0, < 12.4.8 | ≥ 13.0.0, < 13.0.6 | ≥ 13.1.0, < 13.1.3

  • grafanagrafana oss

    ≥ 12.4.0, < 12.4.8 | ≥ 13.0.0, < 13.0.6 | ≥ 13.1.0, < 13.1.3

References (3)