CyberRota Analysis
AI-GeneratedA vulnerability exists in Grafana that allows organization administrators to delete dashboard snapshots belonging to other organizations within the same instance, due to broken access control mechanisms. Additionally, these administrators can recover a snapshot's secret delete key using only its public share key, potentially leading to unauthorized data exposure or loss. Organizations utilizing Grafana should prioritize addressing this issue to safeguard their data integrity and prevent unauthorized access.
Original NVD Description
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).