Medium severity5.4NVD Advisory· Published Sep 30, 2026
CVE-2026-13720
CVE-2026-13720
Description
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.