CVE-2026-28374
Analyzed
Analyzed - Analysis Complete
BaseFortify
Publication date: 2026-05-13
Last updated on: 2026-06-02
Assigner: Grafana Labs
Description
Description
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| grafana | grafana | From 12.2.0 (inc) to 12.2.8 (exc) |
| grafana | grafana | From 12.3.0 (inc) to 12.3.6 (exc) |
| grafana | grafana | 11.6.14 |
| grafana | grafana | 12.2.8 |
| grafana | grafana | 12.3.6 |
| grafana | grafana | From 12.4.0 (inc) to 12.4.3 (exc) |
| grafana | grafana | 11.6.14 |
| grafana | grafana | 12.2.8 |
| grafana | grafana | 12.3.6 |
| grafana | grafana | 13.0.0 |
| grafana | grafana | 13.0.1 |
| grafana | grafana | 12.4.3 |
| grafana | grafana | From 8.5.0 (inc) to 11.6.14 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |