
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-81841 is a missing authorization vulnerability in Grafana OSS and Grafana Enterprise affecting the shared (public) dashboard feature. When a shared dashboard is paused, its access token is not revoked for the frontend bootstrap data endpoints, allowing anyone with the dashboard link to retrieve data source configurations and stored credentials without authentication. The vulnerability was published on September 29, 2026, and affects Grafana versions 11.6.0–11.6.17, 12.0.0–12.0.10, 12.1.0–12.1.10, 12.2.0–12.2.11, 12.3.0–12.3.11, 12.4.0–12.4.11, 13.0.0–13.0.9, 13.1.0–13.1.6, and 13.2.0–13.2.2. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Grafana Advisory).
The root cause is CWE-862 (Missing Authorization): when a shared dashboard is paused, Grafana fails to invalidate the associated access token for the API endpoints that serve frontend bootstrap data. An attacker who possesses the shared dashboard URL can send unauthenticated HTTP requests to these bootstrap endpoints and receive the full data source configuration, including stored credentials for data sources configured with browser-access mode. Notably, deleting the shared dashboard does properly revoke the token, confirming the flaw is specific to the pause operation's token lifecycle management (GitHub Advisory, Grafana Advisory).
Successful exploitation allows an unauthenticated attacker holding a paused shared dashboard link to retrieve the configuration of the dashboard's data sources, including stored credentials for data sources using browser access mode. This constitutes a confidentiality breach that could expose database passwords, API keys, or other sensitive credentials stored within Grafana data source configurations. While integrity and availability are not directly impacted, exposed credentials could enable lateral movement into backend systems connected to those data sources (GitHub Advisory, Grafana Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Grafana Advisory). The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability is automatable (no user interaction required) and requires no authentication, only possession of a paused shared dashboard URL. It has not been added to the CISA Known Exploited Vulnerabilities catalog.
/api/frontend/settings or similar bootstrap endpoints served to the shared dashboard context)./api/frontend/settings, /api/ds/query) originating from unexpected IP addresses using a shared dashboard token associated with a paused dashboard.Grafana has released patched versions addressing this vulnerability. Users should upgrade to: 11.6.18+, 12.0.11+, 12.1.11+, 12.2.12+, 12.3.12+, 12.4.12+, 13.0.10+, 13.1.7+, or 13.2.3+. As an immediate workaround, delete (rather than pause) shared dashboards that are no longer needed, since deletion properly revokes the access token. Additionally, review Grafana access logs for unauthorized access to paused shared dashboards, restrict dashboard sharing to trusted recipients, and audit data source credentials that may have been exposed (Grafana Advisory, GitHub Advisory).
The vulnerability was disclosed by Grafana's security team on September 29, 2026, with a corresponding GitHub Advisory (GHSA-4jjr-w7m9-wx5q) published the same day. Community tracking was noted on Bluesky and various CVE aggregator platforms shortly after disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database entries (GitHub Advisory, Grafana Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."