AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-28378

LOW · CVSS 3.1 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The vulnerability allows an Org Admin to delete public dashboards from other organizations due to a lack of proper isolation in the deletion endpoint. This could lead to unauthorized data loss and disruption of services for affected organizations. Organizations using this dashboard feature should prioritize addressing this issue to prevent potential misuse.

CVE
CVE-2026-28378
Severity
LOW
CVSS
3.1
EPSS
0.14%

Original NVD Description

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)