Unrated severityNVD Advisory· Published Aug 26, 2026· Updated Aug 26, 2026
Broken access control in dashboard snapshots
CVE-2026-19197
Description
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- grafana.com/security/security-advisories/cve-2026-19197mitrevendor-advisory
News mentions
0No linked articles in our index yet.