CVE-2026-21722

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:11.6.10:-:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:12.1.6:-:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:12.2.4:-:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:12.3.2:-:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-12 09:16

Updated : 2026-02-27 15:16


NVD link : CVE-2026-21722

Mitre link : CVE-2026-21722

CVE.ORG link : CVE-2026-21722


JSON object : View

Products Affected

grafana

  • grafana
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-863

Incorrect Authorization