CVE-2026-21722: Public Dashboards time range restriction on annotations can be bypassed
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.
This did not leak any annotations that would not otherwise be visible on the public dashboard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21722?
CVE-2026-21722 has been classified as a medium severity vulnerability.
How do I fix CVE-2026-21722?
To fix CVE-2026-21722, update Grafana to the latest version that addresses this vulnerability.
What is the impact of CVE-2026-21722?
CVE-2026-21722 allows unauthorized users to access and read the entire history of annotations on public dashboards.
Which versions of Grafana are affected by CVE-2026-21722?
CVE-2026-21722 affects Grafana versions from 9.3.0 to 11.6.10 and various versions in the 12.x series.
Are there any workarounds for CVE-2026-21722?
Currently, there are no official workarounds for CVE-2026-21722 other than applying the available updates.