CVE-2026-13720: 
Grafana Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-13720 is an improper authorization vulnerability in Grafana's dashboard API, described as "Dashboard modification lockout via forged file-provisioning metadata." An authenticated user with the Editor role can set file-provisioning metadata annotations (grafana.app/managedBy, grafana.app/managerId, and grafana.app/sourcePath) when creating a dashboard via the API, because these fields are stored without an authorization check. This causes the dashboard to appear as file-provisioned, preventing administrators from updating or deleting it through Grafana. The vulnerability affects Grafana OSS and Grafana Enterprise versions 12.0.0–12.0.10, 12.1.0–12.1.10, 12.2.0–12.2.11, 12.3.0–12.3.11, 12.4.0–12.4.11, 13.0.0–13.0.9, 13.1.0–13.1.6, and 13.2.0–13.2.2. It was published on September 30, 2026, with a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Detalhes técnicos

The root cause is a missing authorization check (CWE-285: Improper Authorization; also classified under CWE-345: Insufficient Verification of Data Authenticity and CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes) when processing dashboard creation requests via the Grafana dashboard API. An Editor-role user can include the grafana.app/managedBy, grafana.app/managerId, and grafana.app/sourcePath annotations in the API request body, and Grafana stores these fields without verifying whether the caller is authorized to set provisioning metadata. Once stored, Grafana treats the dashboard as file-provisioned, which by design restricts administrative modification or deletion through the UI. The attack requires only low privileges (Editor role) and is network-accessible with no user interaction required (GitHub Advisory, Red Hat Bugzilla).

Impacto

Successful exploitation allows an authenticated Editor to permanently lock administrators out of modifying or deleting specific dashboards within the same Grafana organization. The integrity impact is low (unauthorized metadata is written), and the availability impact is low (administrative management of affected dashboards is disrupted). No data is exposed and there is no confidentiality impact; the blast radius is confined to the organization in which the attacker holds the Editor role, with no cross-organization or lateral movement potential (GitHub Advisory, Red Hat Bugzilla).

Exploração

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, indicating very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is not automatable and requires an authenticated Editor-role account within the target organization (GitHub Advisory, Grafana Advisory).

Etapas de exploração

  1. Obtain Editor credentials: Acquire or use an existing Grafana account with the Editor role within the target organization.
  2. Craft a malicious dashboard creation request: Prepare an HTTP POST request to the Grafana dashboard API endpoint (e.g., POST /api/dashboards/db) with a valid dashboard JSON payload.
  3. Inject provisioning metadata annotations: Include the unauthorized annotations in the request body, for example:
{
  "dashboard": { ... },
  "meta": {
    "annotations": {
      "grafana.app/managedBy": "file",
      "grafana.app/managerId": "fake-provisioner",
      "grafana.app/sourcePath": "/etc/grafana/provisioning/dashboards/fake.yaml"
    }
  }
}
  1. Submit the request: Send the crafted API request using a tool such as curl or Burp Suite, authenticated with the Editor's session token or API key.
  2. Verify lockout: Confirm that the dashboard now appears as file-provisioned in the Grafana UI, and that administrator accounts receive an error when attempting to edit or delete it through the interface (GitHub Advisory, Red Hat Bugzilla).

Indicadores de compromisso

  • Logs: Grafana API access logs showing POST /api/dashboards/db requests from Editor-role accounts that include grafana.app/managedBy, grafana.app/managerId, or grafana.app/sourcePath annotation fields in the request body.
  • Application State: Dashboards in the Grafana database that have file-provisioning annotations set but do not correspond to any actual provisioning configuration files on disk.
  • Logs: Grafana audit logs (if enabled) recording dashboard creation events by Editor-role users with unexpected provisioning metadata fields.
  • Application State: Administrator complaints or errors when attempting to edit or delete specific dashboards, with Grafana returning messages indicating the dashboard is managed by a provisioner (GitHub Advisory).

Mitigação e soluções alternativas

Grafana has released patched versions for both OSS and Enterprise editions. Users should upgrade to one of the following fixed versions: 12.0.11, 12.1.11, 12.2.12, 12.3.12, 12.4.12, 13.0.10, 13.1.7, or 13.2.3. As a temporary workaround prior to patching, administrators should restrict the Editor role to trusted users only within their Grafana organizations. Reviewing existing dashboards for unexpected file-provisioning annotations is also recommended to identify any dashboards already affected (Grafana Advisory, GitHub Advisory).

Reações da comunidade

Red Hat tracked the vulnerability via Bugzilla (Bug 2543886) and assigned it medium severity, with the product security team coordinating response across affected packages. The GitHub Advisory Database published the advisory on September 30, 2026, classifying it as "Moderate." No notable independent researcher commentary or significant social media discussion has been observed beyond standard vulnerability aggregator coverage (Red Hat Bugzilla, GitHub Advisory).

Recursos adicionais

Status correto da distribuição Linux

Disponibilidade de correção em distribuições Linux principais e suas versões.

RHEL / CentOS

Afetados

RHEL 8

Não Afetado

RHEL 9

Não Afetado

RHEL 10

grafana.src

Afetados

Origem: Este relatório foi gerado usando IA

Relacionado Grafana Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-83663HIGH8.7
  • Grafana logoGrafana
  • grafana
NãoSimOct 02, 2026
CVE-2026-94637HIGH8.2
  • Grafana logoGrafana
  • grafana.src
NãoSimOct 02, 2026
CVE-2023-54404HIGH8.2
  • Grafana logoGrafana
  • cockpit-image-builder
NãoNãoOct 01, 2026
CVE-2026-102990HIGH8.2
  • JavaScript logoJavaScript
  • cargo
NãoSimSep 30, 2026
CVE-2026-13720MEDIUM5.4
  • Grafana logoGrafana
  • grafana-selinux
NãoSimSep 30, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades