CVE-2026-21724
Received
Received - Intake
Authorization Bypass in Grafana OSS Provisioning Contact Points API
Publication date: 2026-03-26
Last updated on: 2026-04-14
Assigner: Grafana Labs
Description
Description
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| grafana | grafana | From 11.6.9 (inc) to 11.6.14 (exc) |
| grafana | grafana | From 12.1.5 (inc) to 12.1.10 (exc) |
| grafana | grafana | From 12.2.2 (inc) to 12.2.8 (exc) |
| grafana | grafana | From 12.3.1 (inc) to 12.3.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-285 | The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. |