PT-2026-4878 · Unknown+2 · Dashboard Permissions Api+2
Se1En
·
Published
2026-01-27
·
Updated
2026-04-22
·
CVE-2026-21721
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
versions prior to 2026-21721
Description
The dashboard permissions API does not verify the target dashboard scope, only checking the
dashboards.permissions:* action. This allows a user with permission management rights on one dashboard to read and modify permissions on other dashboards, resulting in a privilege escalation. The API endpoint in question is the dashboard permissions API. The vulnerable action is dashboards.permissions:*.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Privilege Management
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grafana
Red Os
Dashboard Permissions Api