{"id":"CVE-2026-13720","title":"An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an autho…","summary":"An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an autho…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-285","CWE-345","CWE-915"],"vendor":"Grafana","product":"Grafana OSS","affected":["oss >= 12.0.0 <= 12.0.10","oss >= 12.1.0 <= 12.1.10","oss >= 12.2.0 <= 12.2.11","oss >= 12.3.0 <= 12.3.11","oss >= 12.4.0 < 12.4.12","oss >= 13.0.0 < 13.0.10","oss >= 13.1.0 < 13.1.7","oss >= 13.2.0 < 13.2.3","enterprise >= 12.0.0 <= 12.0.10","enterprise >= 12.1.0 <= 12.1.10","enterprise >= 12.2.0 <= 12.2.11","enterprise >= 12.3.0 <= 12.3.11","enterprise >= 12.4.0 < 12.4.12","enterprise >= 13.0.0 < 13.0.10","enterprise >= 13.1.0 < 13.1.7","enterprise >= 13.2.0 < 13.2.3"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T17:23:08.953","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13720","references":[{"url":"https://grafana.com/security/security-advisories/cve-2026-13720","label":"security@grafana.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13720.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-13720"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2543886"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-13720"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13720"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-30T13:55:59.494551Z"},"ingestedAt":"2026-09-30T12:02:58.582Z","slug":"CVE-2026-13720","body":"## Overview\n\nAn Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, Red Hat Enterprise Linux 10, … · no fix planned: Multicluster Global Hub, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · updated 2026-09-30 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13720.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}