CVE-2026-33381: Users can generate Service Account tokens after permissions removal
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33381?
The severity of CVE-2026-33381 is rated as high with a CVSS score of 8.1.
What does CVE-2026-33381 describe?
CVE-2026-33381 describes a vulnerability where users can still generate Service Account tokens for a brief period after their permissions have been revoked.
How do I fix CVE-2026-33381?
To fix CVE-2026-33381, ensure that access revocation processes are immediate and thoroughly validated in your Grafana configuration.
What impact does CVE-2026-33381 have on security?
CVE-2026-33381 poses a risk because it allows unauthorized access to sensitive Service Account tokens, potentially leading to data exposure.
Is CVE-2026-33381 specific to any software?
Yes, CVE-2026-33381 specifically affects Grafana software.