CVE-2026-13720: Editor can forge file-provisioning provenance on dashboards via the dashboard API
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A user with the Editor role can exploit it through the dashboard API. The impact is limited to the same Grafana organization.
What access does an attacker need?
The attacker needs authenticated Editor-level privileges and access to create a dashboard through the dashboard API. No user interaction is required.
What is the practical impact on affected dashboards?
An Editor can add file-provisioning annotations so a dashboard appears to be file-provisioned. Administrators may then be unable to update or delete that dashboard through Grafana; no data exposure is described.