CVE-2026-0713: High severity grafana vulnerability
Published Jan 15, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
grafana=any
Remediation
Information
Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
Event History
Jan 15, 2026
CVE Published
via MITRE·01:10 PM
Rejected
via MITRE·01:10 PM
Data Sourced
via NVD·01:16 PM
Description
Jan 22, 2026
Rejected
via MITRE·05:03 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-0713?
CVE-2026-0713 is considered a critical vulnerability as it allows authenticated users to bypass permissions and access all dashboards and folders.
2
How do I fix CVE-2026-0713?
To fix CVE-2026-0713, update Grafana to a version that patches this vulnerability as per the official release notes.
3
Who is affected by CVE-2026-0713?
CVE-2026-0713 affects all users of Grafana, as any authenticated user can exploit the vulnerability across all API versions.
4
What is the impact of CVE-2026-0713?
The impact of CVE-2026-0713 includes unauthorized viewing and editing of dashboards and folders regardless of assigned permissions.
5
Is CVE-2026-0713 related to all Grafana versions?
Yes, CVE-2026-0713 affects all versions of Grafana since it impacts all API endpoints.