Description
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue.

Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions.

Broken access control can allow attackers to:
Access resources only accessible to certain users, thus allowing unauthorized access to data
Perform operations on behalf of other users, leading to account takeovers in the worst cases
Attempt privilege escalation
Attempt to take over an account
Published: 2026-07-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in Grafana IRM that permits users to bypass built‑in access controls and view or act upon data they should not be able to access. An attacker can exploit this broken authorization to read restricted information, perform actions on behalf of other users, and potentially attempt privilege escalation or account takeover as described. The flaw is classified under CWE-284—Broken Access Control.

Affected Systems

Affected vendors and products include Grafana IRM. Specific version information is not provided.

Risk and Exploitability

Risk is high, as a CVSS score of 7.1 falls into the high severity range. The EPSS score is reported as less than 1%, indicating a low likelihood of exploitation at the moment, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be via the Grafana web interface or API, as the description references a web application. Attack would require authentication but the controls used to restrict data visibility or actions are improperly enforced, allowing an authenticated user to reach beyond their intended scope.

Generated by OpenCVE AI on August 3, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied fix for Grafana IRM that resolves the broken access control vulnerability.
  • If a patch is not yet available, enforce role‑based access restrictions so that users have only the permissions they need, and consider disabling any broad or administrative roles in the Grafana cloud environment.
  • Enable multi‑factor authentication for all users to reduce the risk of account takeover.
  • Monitor Grafana logs for unexpected data access patterns or actions by authenticated users, and investigate any anomalies promptly.

Generated by OpenCVE AI on August 3, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana grafana
Vendors & Products Grafana
Grafana grafana

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account
Title CVE-2026-9765 CVE Record
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2026-07-24T14:47:18.667Z

Reserved: 2026-05-27T19:51:51.271Z

Link: CVE-2026-9765

cve-icon Vulnrichment

Updated: 2026-07-24T14:47:04.157Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T13:18:31.480

Modified: 2026-07-30T19:30:33.710

Link: CVE-2026-9765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses