A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-26 21:17
Updated : 2026-03-30 13:26
NVD link : CVE-2026-21724
Mitre link : CVE-2026-21724
CVE.ORG link : CVE-2026-21724
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization
