CVE-2026-72585: Grafana - Incomplete Fix for CVE-2026-21724 Allows Editor Role to Delete Protected Contact Points
Published Aug 10, 2026
·Updated
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
Affected Software
1 affected component
grafana<=13.2.0
Event History
Aug 10, 2026
CVE Published
via MITRE·10:41 AM
Rejected
via MITRE·10:41 AM
Data Sourced
via NVD·11:17 AM
Description
Aug 18, 2026
Rejected
via MITRE·01:04 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-72585?
CVE-2026-72585 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-72585?
To fix CVE-2026-72585, update your Grafana instance to include the relevant patches that address the authorization bypass.
3
What are the implications of CVE-2026-72585?
CVE-2026-72585 allows an unauthorized Editor-role user to delete protected contact points in Grafana.
4
Which versions of Grafana are affected by CVE-2026-72585?
CVE-2026-72585 affects Grafana versions prior to the fixed version released after the vulnerability was disclosed.
5
What does CVE-2026-72585 allow attackers to do?
CVE-2026-72585 allows attackers with the Editor role to delete contact points without necessary permissions, posing a risk to system integrity.