CVE-2026-21727Low· 3.3▾ SunlitA cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user wi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization. This issue affects correlations created prior to Grafana 10.2 and is fixed in >=11.6.11, >=12.0.9, >=12.1.6, and >=12.2.4.
Thanks to Gyu-hyeok Lee (g2h) for reporting this vulnerability.
grafana < 11.6.11grafana >= 12.0.0, < 12.0.9grafana >= 12.1.0, < 12.1.6grafana >= 12.2.0, < 12.2.4grafana >= 12.3.0, < 12.3.3Upgrade past the affected range:
grafana 12.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-14199High· 7.1Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected
CVE-2025-41118Critical· 9.1Pyroscope is an open-source continuous profiling database
CVE-2026-42127High· 7.5The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads
CVE-2026-9029High· 7.3A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable
CVE-2026-10601Medium· 5.4A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints
CVE-2026-21721High· 8.1The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action