CVE-2026-33377

Aliases:CGA-2whr-4qp7-r6h5CGA-fm8v-352h-5j9hCGA-gjh7-75jf-69c9CGA-h7r5-2h2p-8967CGA-h8pg-h863-7562CGA-m2fx-9hc6-72r3CGA-prm5-5f97-p2g6CGA-27q3-2pxf-6xwgCGA-355w-j336-hm9fCGA-4mp3-6r7r-69mqCGA-68wm-5hjh-vhmpCGA-6rp4-6889-vw79CGA-7h28-fcfp-69v5CGA-88vh-xh75-gfgvCGA-8jrv-rgww-mxxmCGA-982v-5qr2-hf88CGA-9cjp-g6rc-f2r3CGA-9fx2-746v-6ccwCGA-cg27-492p-cr2hCGA-cm4q-p34p-c7pfCGA-ffc4-hp88-88xfCGA-g88w-899h-wm76CGA-gf6q-v47c-74w8CGA-jhv2-7jfq-569gCGA-jv36-8789-jp2rCGA-m642-3jh2-p2pwCGA-pp9v-2qpf-mc3fCGA-q45v-m6ph-fgm2CGA-qp7c-wrw5-fx5rCGA-rq45-3x82-rvfpCGA-rq68-j9r9-c5gfCGA-rwjv-g9mp-pfw5CGA-v4jw-4chg-wh55CGA-v5x5-c4g3-8r6jCGA-w339-56gw-rqgqCGA-wcmm-3mmx-v879CGA-wq5m-rh7r-m77mCGA-x2xr-q647-xq9vCGA-x377-rj52-rxvqCGA-x46q-vxvc-mfr8CGA-xrx2-9f36-hh4hCGA-xvpr-2445-6x5p
Analyzed
Published: 13 May 2026, 19:28
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
7.1 HIGH
v3.1 (cve.org)
EPSS Score
0.23% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 May 2026, 19:28
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS Metrics

  • v3.1HIGHScore: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

EPSS Trends

Current EPSS score: 0.23% Percentile: 14%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • chainguardgrafana-12.0

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.4

    < 12.4.3.02-r0

  • chainguardgrafana-fips-12.0

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.4

    < 12.4.4-r0

  • wolfigrafana-12.4

    < 12.4.3.02-r0

  • grafanagrafana

    ≥ 8.5.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1

  • grafanagrafana oss

    ≥ 8.5.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01

References (3)