---
id: CVE-2026-21721
title: >-
  The dashboard permissions API does not verify the target dashboard scope and
  only checks the dashboards.permissions:* action
summary: >-
  The dashboard permissions API does not verify the target dashboard scope and
  only checks the dashboards.permissions:* action. As a result, a user who has
  permission management rights on one dashboard can read and modify permissions
  on ot…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-863
  - CWE-639
vendor: grafana
product: grafana
affected:
  - 'grafana >= 10.2.0, < 11.6.9'
  - 'grafana >= 12.0.0, < 12.0.8'
  - 'grafana >= 12.1.0, < 12.1.5'
  - 'grafana >= 12.2.0, < 12.2.3'
  - grafana = 11.6.9
  - grafana = 12.0.8
  - grafana = 12.1.5
  - grafana = 12.2.3
  - grafana = 12.3.0
  - grafana = 12.3.1
patched:
  - grafana 12.2.3
published: '2026-01-27'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21721'
references:
  - url: 'https://grafana.com/security/security-advisories/cve-2026-21721'
    label: security@grafana.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:2914'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:2920'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:3078'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:3529'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5633'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8229'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-21721'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2433242'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21721.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
  - exploit-available
epss: 0.00735
epssPercentile: 0.52495
ingestedAt: '2026-06-30T17:40:12.466Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Leonideath/Exploit-LPE-CVE-2026-21721'
  checkedAt: '2026-09-26T09:05:40.121Z'
exploitAvailable: true
---

## Overview

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

## Affected

- `grafana >= 10.2.0, < 11.6.9`
- `grafana >= 12.0.0, < 12.0.8`
- `grafana >= 12.1.0, < 12.1.5`
- `grafana >= 12.2.0, < 12.2.3`
- `grafana = 11.6.9`
- `grafana = 12.0.8`
- `grafana = 12.1.5`
- `grafana = 12.2.3`
- `grafana = 12.3.0`
- `grafana = 12.3.1`

## Remediation

Upgrade past the affected range:

- `grafana 12.2.3`
