Medium severity6.3NVD Advisory· Published Aug 26, 2026· Updated Aug 31, 2026
CVE-2026-19197
CVE-2026-19197
Description
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versions
>= 12.4.0, < 12.4.8+ 1 more
- (no CPE)range: >= 12.4.0, < 12.4.8
- (no CPE)range: < 12.4.10-1.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.