Description
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 30 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed. | |
| Title | Editor can forge file-provisioning provenance on dashboards via the dashboard API | |
| Weaknesses | CWE-285 CWE-345 CWE-915 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-09-30T11:06:38.177Z
Reserved: 2026-06-29T14:11:02.739Z
Link: CVE-2026-13720
No data.
Status : Received
Published: 2026-09-30T11:16:43.893
Modified: 2026-09-30T11:16:43.893
Link: CVE-2026-13720
No data.
OpenCVE Enrichment
No data.