---
id: CVE-2026-21724
aliases:
  - GHSA-7g92-g4vh-hp84
  - BIT-grafana-2026-21724
  - GO-2026-5219
title: >-
  Grafana OSS: Authorization bypass allows users with Editor role to modify
  protected webhook URLs without permissions
summary: >-
  Grafana OSS: Authorization bypass allows users with Editor role to modify
  protected webhook URLs without permissions
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
vendor: grafana
product: github.com/grafana/grafana
ecosystem: go
affected:
  - github.com/grafana/grafana < 1.9.2-0.20260323180334-daffe750de85
patched:
  - github.com/grafana/grafana 1.9.2-0.20260323180334-daffe750de85
published: '2026-03-26'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:59.974994795Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7g92-g4vh-hp84'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21724'
  - url: >-
      https://github.com/grafana/grafana/commit/daffe750de85b0dbf79f206a35835cf66a83d6ca
  - url: 'https://github.com/advisories/GHSA-7g92-g4vh-hp84'
  - url: 'https://github.com/grafana/grafana'
  - url: 'https://github.com/grafana/grafana/releases/tag/v12.3.6'
  - url: 'https://grafana.com/security/security-advisories/cve-2026-21724'
tags:
  - osv
  - go
epss: 0.00263
epssPercentile: 0.16109
ingestedAt: '2026-07-21T19:04:58.264Z'
---

## Overview

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

A patched version is available at https://github.com/grafana/grafana/releases/tag/v12.3.6.

## Affected packages

- `github.com/grafana/grafana < 1.9.2-0.20260323180334-daffe750de85`

## Remediation

Upgrade to a patched release:

- `github.com/grafana/grafana 1.9.2-0.20260323180334-daffe750de85`
