{"id":"CVE-2026-21721","title":"The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action","summary":"The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-863","CWE-639"],"vendor":"grafana","product":"grafana","affected":["grafana >= 10.2.0, < 11.6.9","grafana >= 12.0.0, < 12.0.8","grafana >= 12.1.0, < 12.1.5","grafana >= 12.2.0, < 12.2.3","grafana = 11.6.9","grafana = 12.0.8","grafana = 12.1.5","grafana = 12.2.3","grafana = 12.3.0","grafana = 12.3.1"],"patched":["grafana 12.2.3"],"published":"2026-01-27","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-21721","references":[{"url":"https://grafana.com/security/security-advisories/cve-2026-21721","label":"security@grafana.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2914","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:2920","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:3078","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:3529","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:5633","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8229","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-21721","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433242","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21721.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","exploit-available"],"epss":0.00688,"epssPercentile":0.51318,"ingestedAt":"2026-06-30T17:40:12.466Z","exploits":{"github":1,"githubRepos":["https://github.com/Leonideath/Exploit-LPE-CVE-2026-21721"],"checkedAt":"2026-09-24T07:53:00.722Z"},"exploitAvailable":true,"slug":"CVE-2026-21721","body":"## Overview\n\nThe dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.\n\n## Affected\n\n- `grafana >= 10.2.0, < 11.6.9`\n- `grafana >= 12.0.0, < 12.0.8`\n- `grafana >= 12.1.0, < 12.1.5`\n- `grafana >= 12.2.0, < 12.2.3`\n- `grafana = 11.6.9`\n- `grafana = 12.0.8`\n- `grafana = 12.1.5`\n- `grafana = 12.2.3`\n- `grafana = 12.3.0`\n- `grafana = 12.3.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `grafana 12.2.3`","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5009,"id":"CVE-2026-21721","ts":1788887227942,"field":"exploit_available","old":"false","new":"true"},{"seq":3892,"id":"CVE-2026-21721","ts":1788886358869,"field":"exploit_available","old":"true","new":"false"},{"seq":2714,"id":"CVE-2026-21721","ts":1788883024573,"field":"exploit_available","old":"false","new":"true"},{"seq":1743,"id":"CVE-2026-21721","ts":1788882428578,"field":"exploit_available","old":"true","new":"false"},{"seq":849,"id":"CVE-2026-21721","ts":1788881861860,"field":"exploit_available","old":"false","new":"true"}]}