Impact
The public dashboard deletion endpoint in Grafana fails to enforce organization isolation. An administrator with Org Admin privileges can send a request that specifies dashboard identifiers from another organization, which causes those dashboards to be deleted. This results in unauthorized removal of data and loss of functionality; the flaw is an improper access control weakness, identified as CWE-284.
Affected Systems
This vulnerability affects all Grafana Enterprise and Grafana OSS instances, regardless of version, because no specific affected version information is provided. Any instance that exposes the public dashboard deletion endpoint is vulnerable.
Risk and Exploitability
The CVSS score of 3.1 classifies the vulnerability as low severity. The EPSS score is in the (< 1%) interval, indicating a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector requires an internal Org Admin who can send crafted requests to the deletion endpoint, and it is limited to environments where such users have network access to the Grafana instance and the public deletion API is exposed.
OpenCVE Enrichment