CVE-2024-9476

MEDIUM

Grafana Labs Grafana OSS/Enterprise - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance.

Scores

CVSS v4 5.1
EPSS 0.0021
EPSS Percentile 11.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266
Status published
Products (2)
Grafana Labs/Grafana OSS and Enterprise 11.2.0 - 11.2.3+security-01
Grafana Labs/Grafana OSS and Enterprise 11.3.0 - 11.3.0+security-01
Published Nov 13, 2024
Tracked Since Feb 18, 2026