CVE-2026-13720
Received Received - Intake

Grafana Dashboard File-Provisioning Metadata Authorization Bypass

Vulnerability report for CVE-2026-13720, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Grafana Labs

Description

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
grafana grafana *
grafana grafana to 13.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an Editor in Grafana to forge file-provisioning metadata on dashboards via the dashboard API. The Editor can set specific annotations (grafana.app/managedBy, grafana.app/managerId, grafana.app/sourcePath) without proper authorization checks. This makes the dashboard appear as if it was file-provisioned, which prevents administrators from updating or deleting it through Grafana.

Detection Guidance

Check Grafana versions before 12.0.0, 12.4.12, 13.0.0, 13.0.10, 13.1.0, 13.1.7, 13.2.0, or 13.2.3. Review dashboard API logs for unauthorized metadata changes like grafana.app/managedBy, grafana.app/managerId, or grafana.app/sourcePath.

Impact Analysis

The impact is limited to the same organization. Administrators may lose the ability to manage dashboards created by Editors due to the forged file-provisioning status. No data is exposed, but dashboard management could be disrupted.

Compliance Impact

This vulnerability does not directly expose data, so it likely has minimal impact on GDPR or HIPAA compliance. However, it could affect integrity controls by allowing unauthorized changes to dashboard metadata, potentially violating record-keeping or audit requirements in regulated environments.

Mitigation Strategies

Upgrade Grafana to a patched version (12.0.0 or later, 12.4.12, 13.0.10, 13.1.7, 13.2.3, or newer). Review and remove any affected dashboards created by unauthorized users. Monitor for unauthorized metadata changes in API logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13720. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart