SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19197

MEDIUM · CVSS 6.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability exists in Grafana that allows organization administrators to delete dashboard snapshots belonging to other organizations within the same instance, due to broken access control mechanisms. Additionally, these administrators can recover a snapshot's secret delete key using only its public share key, potentially leading to unauthorized data exposure or loss. Organizations utilizing Grafana should prioritize addressing this issue to safeguard their data integrity and prevent unauthorized access.

CVE
CVE-2026-19197
Severity
MEDIUM
CVSS
6.3
EPSS
0.20%

Original NVD Description

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).