PT-2026-4878 · Unknown+3 · Dashboard Permissions Api+3
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
versions prior to 2026-21721
Description
The dashboard permissions API does not verify the target dashboard scope, only checking the
dashboards.permissions:* action. This allows a user with permission management rights on one dashboard to read and modify permissions on other dashboards, resulting in a privilege escalation. The API endpoint in question is the dashboard permissions API. The vulnerable action is dashboards.permissions:*.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
DoS
Incorrect Authorization
IDOR
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grafana
Red Os
Rocky Linux
Dashboard Permissions Api