Impact
The description explains that the cross‑tenant data disclosure and deletion flaw arises from Grafana’s Correlations feature, where legacy records tagged with org_id=0 are inadvertently returned to all organizations. A user with datasource‑management privileges can read and permanently delete these legacy correlation entries, potentially exposing sensitive information and erasing critical analytics data. This misconfiguration in access control produces unauthorized disclosure and modification of data across tenants.
Affected Systems
Grafana Correlations is affected. Vulnerable installations include any Grafana 10.x version or Grafana 11.x prior to 11.6.10, Grafana 12.0.x prior to 12.0.9, Grafana 12.1.x prior to 12.1.6, and Grafana 12.2.x prior to 12.2.4. Correlations created before Grafana 10.2 are also impacted.
Risk and Exploitability
Based on the description, the attack vector involves a user with datasource‑management privileges accessing the legacy correlation records. The CVSS score of 3.3 classifies the vulnerability as low severity; the EPSS score of <1% indicates a very low likelihood of real‑world exploitation, and it is not listed in the KEV catalog. To exploit the flaw, an attacker would need to possess or compromise an account that has datasource‑management privileges within Grafana and then access the legacy correlation records, read their contents and perform delete operations that permanently erase the data.
OpenCVE Enrichment