PT-2026-21901 · Grafana · Grafana
Se1En
·
Published
2026-02-25
·
Updated
2026-05-10
·
CVE-2026-21725
CVSS v3.1
2.6
Low
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Grafana (affected versions not specified)
Description
A time-of-create-to-time-of-use (TOCTOU) issue allows re-deletion of recently deleted and recreated data sources without authorization. The attack requires specific conditions: admin access to the data source before initial deletion, all steps completed within 30 seconds on the same Grafana pod, recreation of the data source by another user, the new data source having the same UID as the previous one, and the attacker not being an admin of the new data source.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana