Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana
Grafana grafana Grafana grafana Enterprise |
|
| Vendors & Products |
Grafana
Grafana grafana Grafana grafana Enterprise |
Wed, 30 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed. | |
| Title | Editor can forge file-provisioning provenance on dashboards via the dashboard API | |
| Weaknesses | CWE-285 CWE-345 CWE-915 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-09-30T15:28:07.969Z
Reserved: 2026-06-29T14:11:02.739Z
Link: CVE-2026-13720
No data.
Status : Awaiting Analysis
Published: 2026-09-30T11:16:43.893
Modified: 2026-09-30T17:23:08.953
Link: CVE-2026-13720
OpenCVE Enrichment
Updated: 2026-09-30T20:15:05Z