Impact
The vulnerability is a broken access control flaw that lets an organization‑administrator user delete or recover dashboard snapshots belonging to other organizations on the same Grafana instance. Because the snapshot share key can be used to obtain the secret delete key, an attacker can also bypass deletion restrictions, leading to data loss and potential exposure of sensitive information.
Affected Systems
Affected systems include all versions of Grafana Enterprise and Grafana OSS. No specific product versions are listed, so every Grafana instance should be evaluated for the presence of this flaw until an official fix is applied.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity, and the vulnerability is not listed in CISA's KEV catalog. Without an EPSS score, the precise likelihood of exploitation is unknown, but the flaw requires an existing organization‑administrator account and an ability to share a dashboard snapshot. Once those conditions are met, the attacker can delete snapshots from other organizations and expose secret delete keys, potentially compromising data integrity and confidentiality.
OpenCVE Enrichment