Description
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Published: 2026-08-26
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw that lets an organization‑administrator user delete or recover dashboard snapshots belonging to other organizations on the same Grafana instance. Because the snapshot share key can be used to obtain the secret delete key, an attacker can also bypass deletion restrictions, leading to data loss and potential exposure of sensitive information.

Affected Systems

Affected systems include all versions of Grafana Enterprise and Grafana OSS. No specific product versions are listed, so every Grafana instance should be evaluated for the presence of this flaw until an official fix is applied.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity, and the vulnerability is not listed in CISA's KEV catalog. Without an EPSS score, the precise likelihood of exploitation is unknown, but the flaw requires an existing organization‑administrator account and an ability to share a dashboard snapshot. Once those conditions are met, the attacker can delete snapshots from other organizations and expose secret delete keys, potentially compromising data integrity and confidentiality.

Generated by OpenCVE AI on August 26, 2026 at 10:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Grafana to a patched version that resolves the broken access control flaw.
  • Limit organization‑administrator privileges to trusted users only and review role assignments.
  • Disable or lock public sharing of dashboard snapshots to prevent unintended exploitation of share keys.

Generated by OpenCVE AI on August 26, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Title Broken access control in dashboard snapshots
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2026-08-26T13:48:49.617Z

Reserved: 2026-08-06T20:25:58.163Z

Link: CVE-2026-19197

cve-icon Vulnrichment

Updated: 2026-08-26T13:44:40.235Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T10:30:04Z

Weaknesses