CVE-2026-9765
Received Received - Intake

Broken Access Control in Grafana

Vulnerability report for CVE-2026-9765, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Grafana Labs

Description

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are β€œBroken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves broken access controls in a web application, allowing attackers to bypass authorization mechanisms and access resources they are not permitted to view or modify. It can lead to unauthorized data access, account takeovers, privilege escalation, and other malicious activities.

Impact Analysis

An attacker could exploit this to access sensitive data, perform actions as another user, escalate privileges, or take over accounts. This could result in data breaches, financial loss, or unauthorized system control depending on the application's role and data.

Compliance Impact

Broken access controls can lead to unauthorized data exposure, violating GDPR's data protection principles and HIPAA's access control requirements. This may result in legal penalties, fines, or loss of compliance certifications.

Mitigation Strategies

Implement strict access control policies and enforce least privilege principles. Regularly audit user permissions and access logs to detect unauthorized access attempts. Ensure web application firewalls are configured to block suspicious requests that attempt to bypass access controls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9765. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart