CVE-2026-28380

Aliases:CGA-3x4x-h6jx-f5hmCGA-726f-p2gg-v4fhCGA-7pcm-f268-24p5CGA-h29g-r98c-5rc7CGA-m2pj-x69w-f9p9CGA-mxph-hx97-j6gfCGA-pcq5-j6pr-x75pCGA-pq8c-pg7h-hmx5CGA-23rm-hgc4-26wpCGA-2cm4-vrp9-g68gCGA-2r88-5mfh-qh97CGA-2xfw-j6x5-h8qrCGA-3rqq-pjjg-p324CGA-4667-9h84-c626CGA-5gx2-2wwr-gjxfCGA-5xm9-v7mq-vmh4CGA-68qg-g273-49m7CGA-6q6m-2wvf-p965CGA-7vx2-j5mv-wfmmCGA-88fx-v85v-3j23CGA-8j9h-m3rj-4g2gCGA-9792-hpm6-6c75CGA-9g78-37v3-47jwCGA-ccw4-96xv-v2h4CGA-crw2-5p2r-2p88CGA-ff24-rvmg-9qpfCGA-fp28-vmvx-37pxCGA-g4xh-jr4r-5gxmCGA-hmcj-xm88-w74vCGA-hr69-6vh8-m3wfCGA-hv5g-fwxx-6wxvCGA-hw9g-4mpx-v6v9CGA-j86m-g64q-4g8cCGA-jrvj-43vq-fpfjCGA-m63j-4c2q-7hqxCGA-m824-58mx-62f3CGA-q54c-353x-v9cgCGA-q8f2-f56x-rmx4CGA-qjw9-37wv-68chCGA-v892-8rgq-jxq6CGA-wqqr-j8r4-66xvCGA-xvrx-fw3r-m68p
Analyzed
Published: 13 May 2026, 19:28
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.23% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 May 2026, 19:28
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.23% Percentile: 14%

Techniques & Countermeasures

  • CWE-862Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Affected Systems

  • chainguardgrafana-12.0

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.4

    < 12.4.3.02-r0

  • chainguardgrafana-fips-12.0

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.4

    < 12.4.4-r0

  • wolfigrafana-12.4

    < 12.4.3.02-r0

  • grafanagrafana

    ≥ 8.5.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1

  • grafanagrafana oss

    ≥ 9.4.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01

References (3)