CVE-2026-19197: Broken access control in dashboard snapshots
Published Aug 26, 2026
·Updated
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Affected Software
1 affected component
Grafana Grafana
Event History
Aug 26, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker needs organization administrator permissions on a Grafana instance. No user interaction is required.
2
What data or functionality can be affected?
An organization administrator can delete dashboard snapshots that belong to other organizations on the same Grafana instance. They can also recover a snapshot's secret delete key using only its public share key.
3
Is this limited to a single organization?
No. The described impact crosses organization boundaries when multiple organizations share the same Grafana instance.