CVE-2025-3260: High severity Grafana Grafana vulnerability
A security vulnerability in the /apis/dashboard.grafana.app/ endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1).
Impact:
- Viewers can view all dashboards/folders regardless of permissions
- Editors can view/edit/delete all dashboards/folders regardless of permissions
- Editors can create dashboards in any folder regardless of permissions
- Anonymous users with viewer/editor roles are similarly affected
Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3260?
CVE-2025-3260 has a high severity as it allows authenticated users to bypass dashboard and folder permissions.
How do I fix CVE-2025-3260?
To fix CVE-2025-3260, upgrade Grafana to a version that addresses this vulnerability.
Who is affected by CVE-2025-3260?
CVE-2025-3260 affects all users of Grafana versions v0alpha1, v1alpha1, and v2alpha1.
What are the risks of CVE-2025-3260?
The risks of CVE-2025-3260 include unauthorized access to all dashboards and folders, compromising data confidentiality.
Can CVE-2025-3260 be exploited remotely?
CVE-2025-3260 requires authenticated access, but once authenticated, it can be exploited by users with limited permissions.