github.com
https://github.com/grafana/grafana CVE-2026-33381
MEDIUM
Users can generate Service Account tokens after permissions removal
Record summary
CVE-2026-33381 has a selected CVSS score of 5.9 (medium).
Description
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Grafana OSSBrowse Grafana / Grafana OSSDefault status: unaffected | CVE List | 9.2.0 to ≤ 11.6.14 | affected |
| 11.6.14 to < 11.6.14+security-04 | affected | ||
| 12.0.0 to ≤ 12.2.8 | affected | ||
| 12.2.8 to < 12.2.8+security-04 | affected | ||
| 12.3.0 to ≤ 12.3.6 | affected | ||
| 12.3.6 to < 12.3.6+security-04 | affected | ||
| 12.4.0 to ≤ 12.4.3 | affected | ||
| 12.4.3 to < 12.4.3+security-02 | affected | ||
| 13.0.0 to ≤ 13.0.1 | affected | ||
| 13.0.1 to < 13.0.1+security-01 | affected | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | Before 1.9.2-0.20260513165311-fb7336fc36c1 · Fixed in 1.9.2-0.20260513165311-fb7336fc36c1 | affected |
References
4github.com
https://github.com/grafana/grafana/commit/fb7336fc36c14e1ff869482c5085ddb9f39e1b86 grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2026-33381 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-33381