Record summary

CVE-2026-33381 has a selected CVSS score of 5.9 (medium).

Description

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List9.2.0 to ≤ 11.6.14affected
11.6.14 to < 11.6.14+security-04affected
12.0.0 to ≤ 12.2.8affected
12.2.8 to < 12.2.8+security-04affected
12.3.0 to ≤ 12.3.6affected
12.3.6 to < 12.3.6+security-04affected
12.4.0 to ≤ 12.4.3affected
12.4.3 to < 12.4.3+security-02affected
13.0.0 to ≤ 13.0.1affected
13.0.1 to < 13.0.1+security-01affected

github.com/grafana/grafana

Browse Go / github.com/grafana/grafana
GitHub AdvisoryBefore 1.9.2-0.20260513165311-fb7336fc36c1 · Fixed in 1.9.2-0.20260513165311-fb7336fc36c1affected

References

4