CVE-2026-33377
Vulnerability Summary
Timeline
Description
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
EPSS Trends
Current EPSS score: 0.23%• Percentile: 14%
Techniques & Countermeasures
- CWE-287•Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
- CWE-284•Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Affected Systems
- chainguard•grafana-12.0
all
- chainguard•grafana-12.1
all
- chainguard•grafana-12.4
< 12.4.3.02-r0
- chainguard•grafana-fips-12.0
all
- chainguard•grafana-fips-12.1
all
- chainguard•grafana-fips-12.4
< 12.4.4-r0
- wolfi•grafana-12.4
< 12.4.3.02-r0
- grafana•grafana
≥ 8.5.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1
- grafana•grafana oss
≥ 8.5.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01