PT-2026-21901 · Grafana · Grafana

Se1En

·

Published

2026-02-25

·

Updated

2026-05-10

·

CVE-2026-21725

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Grafana (affected versions not specified)
Description A time-of-create-to-time-of-use (TOCTOU) issue allows re-deletion of recently deleted and recreated data sources without authorization. The attack requires specific conditions: admin access to the data source before initial deletion, all steps completed within 30 seconds on the same Grafana pod, recreation of the data source by another user, the new data source having the same UID as the previous one, and the attacker not being an admin of the new data source.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-2026-21725
CVE-2026-21725
OPENSUSE-SU-2026:10601-1
SUSE-SU-2026:1524-1

Affected Products

Grafana