CVE-2026-21721

Aliases:CGA-2x4w-8q3m-h943CGA-32f2-338r-m8cpCGA-38r5-cg7j-cv2hCGA-3m6p-m9q2-qqxqCGA-4784-84v9-x9wcCGA-4978-c99x-8r8wCGA-66m6-r4vr-v8j9CGA-69g8-h5cr-9cfhCGA-82g7-jc9h-28pqCGA-869r-592g-qp95CGA-9xwm-4v6g-hfgmCGA-cp9h-q363-vjfqCGA-ggfg-5wp4-m48jCGA-h7hf-9625-9h9hCGA-h9vr-8f9r-f5jjCGA-jc47-fwr2-3x9jCGA-v2wq-6h77-9vrcCGA-vx2q-589x-h7g3CGA-w9gg-wrq2-6mc4CGA-wrch-pxq6-23qwCGA-x3wp-6hq3-8w5hCGA-xpxc-p2v5-9r7r
Modified
Published: 27 Jan 2026, 09:07
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
0.69% LOW
1% probability +0.67%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Jan 2026, 09:07
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.69% Percentile: 51%

Techniques & Countermeasures

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • CWE-639Authorization Bypass Through User-Controlled Key

    The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Affected Systems

  • chainguardgrafana-11.4

    all | < 11.4.8-r3

  • chainguardgrafana-11.5

    < 11.5.10-r2

  • chainguardgrafana-fips-11.5

    all

  • grafanagrafana

    ≥ 10.2.0, < 11.6.9 | ≥ 12.0.0, < 12.0.8 | ≥ 12.1.0, < 12.1.5 | ≥ 12.2.0, < 12.2.3 | 11.6.9 | 12.0.8 | 12.1.5 | 12.2.3 | 12.3.0 | 12.3.1

  • grafanagrafana/grafana

    ≥ 12.3.0, < 12.3.1 | ≥ 12.2.0, < 12.2.3 | ≥ 12.1.0, < 12.1.5 | ≥ 12.0.0, < 12.0.8 | ≥ 10.2.0, < 11.6.9

  • grafanagrafana/grafana-enterprise

    ≥ 10.2.0, < 11.6.9 | ≥ 12.0.0, < 12.0.8 | ≥ 12.1.0, < 12.1.5 | ≥ 12.2.0, < 12.2.3 | ≥ 12.3.0, < 12.3.1

References (15)