The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana-selinuxUpgrade grafana | Feb 20, 2026 | Feb 18, 2026 |
| Oracle_linux | — | Upgrade grafana-selinuxUpgrade grafana | Feb 24, 2026 | Jan 27, 2026 |
| Redhat_linux | — | Upgrade grafana-debugsourceUpgrade grafanaUpgrade grafana-debuginfoUpgrade grafana-selinux | Feb 19, 2026 | Jan 27, 2026 |
| Rocky_linux | — | Upgrade grafana-debugsourceUpgrade grafana-selinuxUpgrade grafanaUpgrade grafana-debuginfo | Feb 26, 2026 | Feb 24, 2026 |
| Suse | — | Upgrade golang-github-boynux-squid_exporterUpgrade golang-github-prometheus-promuUpgrade prometheus-blackbox_exporterUpgrade grafanaUpgrade golang-github-lusitaniae-apache_exporterUpgrade dracut-saltbootUpgrade spacecmdUpgrade golang-github-qubitproducts-exporter_exporter | Mar 27, 2026 | Mar 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub