Impact
Cross‑Tenant Legacy Correlation Disclosure and Deletion is a flaw in Grafana’s Correlations feature that allows a user with datasource‑management privileges to read and delete legacy correlation records belonging to other organizations. The issue arises from a backward‑compatibility setting that permits records tagged with org_id=0 to be returned across all tenants. As a result, sensitive correlation data can be exposed and permanently removed by an attacker who has sufficient privileges within Grafana. The weakness is a mis‑configured access control that permits unauthorized disclosure and modification of data.
Affected Systems
Grafana Correlations is affected. Vulnerable installations include any Grafana 10.x version or Grafana 11.x prior to 11.6.10, Grafana 12.0.x prior to 12.0.9, Grafana 12.1.x prior to 12.1.6, and Grafana 12.2.x prior to 12.2.4. Correlations created before Grafana 10.2 are also impacted.
Risk and Exploitability
The CVSS vector indicates that remote exploitation is possible but requires high privilege, specifically datasource‑management rights. The CVSS score of 3.3 classifies the vulnerability as low severity; the EPSS Score of <1% indicates a very low likelihood of real‑world exploitation, and it is not listed in the KEV catalog. To exploit the flaw, an attacker would need to possess or compromise an account that has datasource‑management privileges within Grafana and then access the legacy correlation records, read their contents and perform delete operations that permanently erase the data.
OpenCVE Enrichment