CVE-2026-11817: CWE-863 in Grafana Grafana OSS
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
AI Analysis
Technical Summary
This vulnerability (CWE-863) affects Grafana OSS instances configured with multiple organizations. An Org Admin user in one organization can exploit the GET /api/access-control/users/permissions/search?actionPrefix=dashboards: API endpoint to retrieve permission data for dashboards and folders belonging to other organizations. The information disclosed includes only dashboard and folder UIDs and per-user permission mappings, without exposing dashboard content or sensitive data. This is a limited cross-organization information disclosure issue impacting multi-org setups only.
Potential Impact
The impact is limited to unauthorized disclosure of dashboard and folder identifiers and user permission mappings across organizations in a multi-organization Grafana OSS deployment. No dashboard content, query results, datasource credentials, secrets, or personal data are exposed. This could potentially aid an attacker in reconnaissance but does not directly expose sensitive or confidential data.
Mitigation Recommendations
No vendor advisory or patch links are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should consider restricting Org Admin privileges carefully and monitor access patterns in multi-organization deployments. Single-organization deployments are not affected.
CVE-2026-11817: CWE-863 in Grafana Grafana OSS
Description
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
CVSS v4.0
Score 5.3medium
Affected software
Grafana
Grafana OSS
Grafana
Grafana Enterprise
pkg:github/grafana/grafanaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-863) affects Grafana OSS instances configured with multiple organizations. An Org Admin user in one organization can exploit the GET /api/access-control/users/permissions/search?actionPrefix=dashboards: API endpoint to retrieve permission data for dashboards and folders belonging to other organizations. The information disclosed includes only dashboard and folder UIDs and per-user permission mappings, without exposing dashboard content or sensitive data. This is a limited cross-organization information disclosure issue impacting multi-org setups only.
Potential Impact
The impact is limited to unauthorized disclosure of dashboard and folder identifiers and user permission mappings across organizations in a multi-organization Grafana OSS deployment. No dashboard content, query results, datasource credentials, secrets, or personal data are exposed. This could potentially aid an attacker in reconnaissance but does not directly expose sensitive or confidential data.
Mitigation Recommendations
No vendor advisory or patch links are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should consider restricting Org Admin privileges carefully and monitor access patterns in multi-organization deployments. Single-organization deployments are not affected.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GRAFANA
- Date Reserved
- 2026-06-09T16:24:38.153Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a838032bf8831d5399e475d
Added to database: 08/17/2026, 21:42:10 UTC
Last enriched: 09/19/2026, 01:08:45 UTC
Last updated: 10/02/2026, 11:54:32 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.