CVE-2026-22640: Medium severity grafana/grafana vulnerability
Published Jan 15, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
grafana/grafana
Remediation
Information
Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
Event History
Jan 15, 2026
CVE Published
via MITRE·01:12 PM
Rejected
via MITRE·01:12 PM
Data Sourced
via NVD·02:16 PM
Description
Jan 22, 2026
Rejected
via MITRE·05:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-22640?
CVE-2026-22640 is classified with a critical severity level due to its impact on account management in Grafana OSS.
2
How do I fix CVE-2026-22640?
To fix CVE-2026-22640, ensure that you update Grafana OSS to the latest version that patches this access control vulnerability.
3
Who is affected by CVE-2026-22640?
CVE-2026-22640 affects Grafana OSS installations where Organization administrators have the ability to modify user roles.
4
What actions can be exploited in CVE-2026-22640?
CVE-2026-22640 can be exploited by an Organization administrator to permanently delete the Server administrator account using the DELETE /api/org/users/ endpoint.
5
When was CVE-2026-22640 disclosed?
CVE-2026-22640 was disclosed in 2026, highlighting a critical access control issue in Grafana OSS.