Impact
The vulnerability is a flaw in Grafana IRM that permits users to bypass built‑in access controls and view or act upon data they should not be able to access. An attacker can exploit this broken authorization to read restricted information, perform actions on behalf of other users, and potentially attempt privilege escalation or account takeover as described. The flaw is classified under CWE-284—Broken Access Control.
Affected Systems
Affected vendors and products include Grafana IRM. Specific version information is not provided.
Risk and Exploitability
Risk is high, as a CVSS score of 7.1 falls into the high severity range. The EPSS score is reported as less than 1%, indicating a low likelihood of exploitation at the moment, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be via the Grafana web interface or API, as the description references a web application. Attack would require authentication but the controls used to restrict data visibility or actions are improperly enforced, allowing an authenticated user to reach beyond their intended scope.
OpenCVE Enrichment