grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2026-28378 CVE-2026-28378
LOW
Cross-Organization Public Dashboard Deletion via Missing Org Isolation
Record summary
CVE-2026-28378 has a selected CVSS score of 3.1 (low).
Description
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 8, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Grafana EnterpriseBrowse Grafana / Grafana EnterpriseDefault status: unaffected | CVE List | 11.6.0 to ≤ 11.6.13 | affected |
| 12.1.0 to ≤ 12.1.9 | affected | ||
| 12.2.0 to ≤ 12.2.7 | affected | ||
| 12.3.0 to ≤ 12.3.5 | affected | ||
| 12.4.0 to ≤ 12.4.1 | affected | ||
Grafana OSSBrowse Grafana / Grafana OSSDefault status: unaffected | CVE List | 11.6.0 to ≤ 11.6.13 | affected |
| 12.1.0 to ≤ 12.1.9 | affected | ||
| 12.2.0 to ≤ 12.2.7 | affected | ||
| 12.3.0 to ≤ 12.3.5 | affected | ||
| 12.4.0 to ≤ 12.4.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-28378