CVE-2026-11817: CVE Record
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11817?
The severity of CVE-2026-11817 is rated as risk 26.
Who is affected by CVE-2026-11817?
CVE-2026-11817 affects Grafana stacks configured with multiple organizations, specifically Org Admins of a single organization.
How do I fix CVE-2026-11817?
To mitigate CVE-2026-11817, ensure that your Grafana deployment is single-organization or restrict access appropriately in multi-organization setups.
Does CVE-2026-11817 impact single-organization Grafana deployments?
No, CVE-2026-11817 does not impact single-organization Grafana deployments.
What is the primary risk associated with CVE-2026-11817?
The primary risk associated with CVE-2026-11817 is unauthorized access to user permissions in multi-organization Grafana environments.