Description
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.

This did not leak any annotations that would not otherwise be visible on the public dashboard.
Published: 2026-02-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows a user to retrieve annotations that exist outside the enforced time window of a public dashboard. Because the annotation timerange was not limited to the dashboard’s locked range, an attacker can read the full history of annotations that would otherwise be limited by the dashboard’s time lock. The impact is that sensitive information that the dashboard owner chose to keep hidden within a narrower time frame may be exposed to any viewer who is granted access to the public dashboard. This is an information‑disclosure flaw classified under CWE‑200.

Affected Systems

Grafana (grafana/grafana) and Grafana Enterprise (grafana/grafana-enterprise) installations with versions including 11.6.10, 12.1.6, 12.2.4, 12.3.2, and all earlier builds affected by the CVE. Users should verify the exact Grafana version in use against the vendor release notes.

Risk and Exploitability

The vulnerability scores a CVSS of 5.3, indicating moderate severity. The EPSS score is below 1%, suggesting that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw by accessing a public dashboard that has annotations enabled and may query the annotation API to retrieve annotations outside the locked timerange. No authentication is required beyond the typical public‑dashboard access, so any user who can view the dashboard could potentially read the broader annotation history.

Generated by OpenCVE AI on April 15, 2026 at 17:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Grafana release that contains the vendor patch addressing the annotation timerange restriction.
  • If an immediate upgrade is not possible, disable public dashboard annotation visibility or configure annotation access to require authentication.
  • Regularly review Grafana configuration and audit public dashboards to ensure that annotation settings are appropriately restricted.

Generated by OpenCVE AI on April 15, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Mon, 23 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:11.6.10:-:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:12.1.6:-:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:12.2.4:-:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:12.3.2:-:*:*:*:*:*:*

Fri, 13 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 12 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 13:30:00 +0000

Type Values Removed Values Added
References

Thu, 12 Feb 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana grafana
Grafana grafana Enterprise
Vendors & Products Grafana
Grafana grafana
Grafana grafana Enterprise

Thu, 12 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
Description Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.
Title Public Dashboards time range restriction on annotations can be bypassed
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Grafana Grafana Grafana Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2026-04-24T08:00:47.717Z

Reserved: 2026-01-05T09:26:06.214Z

Link: CVE-2026-21722

cve-icon Vulnrichment

Updated: 2026-02-12T14:24:11.898Z

cve-icon NVD

Status : Modified

Published: 2026-02-12T09:16:08.763

Modified: 2026-02-27T15:16:27.600

Link: CVE-2026-21722

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-02-12T08:49:05Z

Links: CVE-2026-21722 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T17:30:10Z

Weaknesses