
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21724 is an authorization bypass vulnerability in Grafana OSS affecting the provisioning contact points API. It allows authenticated users with the Editor role to modify protected webhook URLs without possessing the required alert.notifications.receivers.protected:write permission. The vulnerability was published on March 26, 2026, and affects Grafana OSS versions 11.6.9–11.6.14, 12.1.5–12.1.10, 12.2.2–12.2.8, and 12.3.1–12.3.6. It carries a CVSS v3.1 base score of 4.3 (Medium) (Grafana Advisory).
The root cause is classified as CWE-285 (Improper Authorization), where the provisioning contact points API endpoint fails to enforce the alert.notifications.receivers.protected:write permission check for users holding the Editor role. An authenticated attacker with low privileges can send a crafted API request to modify protected webhook URLs that should be restricted to higher-privileged roles. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit for any authenticated Editor-level user (Grafana Advisory).
Successful exploitation allows an Editor-level user to tamper with protected webhook URLs used in alerting contact points, potentially redirecting alert notifications to attacker-controlled endpoints. This primarily affects integrity — confidentiality and availability are not directly impacted. In environments where alerting pipelines are critical for incident response, unauthorized modification of webhook URLs could suppress or misdirect security alerts, undermining monitoring and response capabilities (Grafana Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-21724. The EPSS score is approximately 0.027%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated session with at least Editor-level privileges, limiting the attack surface to internal or compromised accounts (Grafana Advisory).
GET /api/v1/provisioning/contact-points) to identify webhook-based receivers marked as protected.PUT or POST request to the provisioning contact points API endpoint targeting a protected webhook receiver, supplying a modified webhook URL pointing to an attacker-controlled server.alert.notifications.receivers.protected:write.PUT or POST requests to /api/v1/provisioning/contact-points by Editor-role users modifying webhook-type receivers, especially outside normal administrative activity.Grafana has released patched versions addressing this vulnerability: 11.6.14, 12.1.10, 12.2.8, and 12.3.6. Organizations should upgrade to the appropriate fixed version as the primary remediation. As a workaround prior to patching, administrators can restrict Editor-role access or audit and monitor the provisioning contact points API for unauthorized modifications. SUSE has also released updated packages for affected Linux distributions (Grafana Advisory, SUSE Advisory).
SUSE issued security update announcements (SUSE-SU-2026:2258-1 and SUSE-SU-2026:2265-1) packaging the Grafana fixes for their distributions, indicating prompt downstream response (SUSE Advisory). Tenable published a Nessus detection plugin (ID 304335) for the vulnerability. No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."