AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-3260

HIGH · CVSS 8.3 EPSS 0.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-06-02 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.3. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-3260
Severity
HIGH
CVSS
8.3
EPSS
0.51%

Original NVD Description

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources.