VYPR
Low severity3.1OSV Advisory· Published Jul 7, 2026· Updated Jul 10, 2026

CVE-2026-28378

CVE-2026-28378

Description

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

Affected products

7
  • Grafana/GrafanaOSV6 versions
    12.4.0, v11.6.13, v12.1.9, …+ 5 more
    • (no CPE)range: 12.4.0, v11.6.13, v12.1.9, …
    • cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*range: >=11.6.0,<=11.6.13
    • cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*range: >=11.6.0,<=11.6.13
    • cpe:2.3:a:grafana:grafana:12.4.0:*:*:*:-:*:*:*
    • cpe:2.3:a:grafana:grafana:12.4.0:*:*:*:enterprise:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 11.6.0, < 11.6.14

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.