CVE Vulnerabilities

CVE-2026-21721

Published: Jan 27, 2026 | Modified: Jan 27, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatgrafana-0:10.2.6-22.el10_1*
Red Hat Enterprise Linux 9RedHatgrafana-0:10.2.6-18.el9_7*

References