GHSA-69w7-2qcg-cvr7MediumCVSS 6.5

An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to...

Published
August 10, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.

🔗 References (5)