The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | grafana-0:10.2.6-22.el10_1 | * |
| Red Hat Enterprise Linux 9 | RedHat | grafana-0:10.2.6-18.el9_7 | * |