grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2026-28374 CVE-2026-28374
MEDIUM
IDOR in Annotations API allows unprivileged users to DELETE annotation
Record summary
CVE-2026-28374 has a selected CVSS score of 4.3 (medium).
Description
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Grafana OSSBrowse Grafana / Grafana OSSDefault status: unaffected | CVE List | 8.5.0 to ≤ 11.6.14 | affected |
| 11.6.14 to < 11.6.14+security-04 | affected | ||
| 12.0.0 to ≤ 12.2.8 | affected | ||
| 12.2.8 to < 12.2.8+security-04 | affected | ||
| 12.3.0 to ≤ 12.3.6 | affected | ||
| 12.3.6 to < 12.3.6+security-04 | affected | ||
| 12.4.0 to ≤ 12.4.3 | affected | ||
| 12.4.3 to < 12.4.3+security-02 | affected | ||
| 13.0.0 to ≤ 13.0.1 | affected | ||
| 13.0.1 to < 13.0.1+security-01 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-28374