Low severity3.1OSV Advisory· Published Jul 7, 2026· Updated Jul 10, 2026
CVE-2026-28378
CVE-2026-28378
Description
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Affected products
712.4.0, v11.6.13, v12.1.9, …+ 5 more
- (no CPE)range: 12.4.0, v11.6.13, v12.1.9, …
- cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*range: >=11.6.0,<=11.6.13
- cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*range: >=11.6.0,<=11.6.13
- cpe:2.3:a:grafana:grafana:12.4.0:*:*:*:-:*:*:*
- cpe:2.3:a:grafana:grafana:12.4.0:*:*:*:enterprise:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
1- grafana.com/security/security-advisories/cve-2026-28378nvdBroken Link
News mentions
0No linked articles in our index yet.