CVE-2026-13720: CWE-285 in Grafana Grafana OSS
CVE-2026-13720 is a medium severity vulnerability in Grafana OSS where an Editor user can set file-provisioning metadata fields when creating dashboards via the API without proper authorization checks. This causes the dashboard to appear file-provisioned, preventing administrators from updating or deleting it through Grafana. The impact is limited to the same organization, with no data exposure reported.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-13720) affects Grafana OSS versions from 12.0.0 up to but not including 13.2.3 in various subversions. An Editor role can set specific file-provisioning metadata annotations (grafana.app/managedBy, grafana.app/managerId, and grafana.app/sourcePath) when creating dashboards through the dashboard API. Because these fields are stored without an authorization check, the dashboard is marked as file-provisioned, which restricts administrators from modifying or deleting it via the Grafana interface. The flaw does not expose data and is scoped to the same organization.
Potential Impact
The vulnerability allows an Editor user to create dashboards that administrators cannot update or delete, potentially causing management and operational issues within the affected organization. There is no data confidentiality impact, but integrity and availability are affected to a limited extent within the same organizational boundary.
Mitigation Recommendations
No explicit patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should review Editor permissions and monitor dashboard provisioning activities to mitigate potential misuse.
CVE-2026-13720: CWE-285 in Grafana Grafana OSS
Description
CVE-2026-13720 is a medium severity vulnerability in Grafana OSS where an Editor user can set file-provisioning metadata fields when creating dashboards via the API without proper authorization checks. This causes the dashboard to appear file-provisioned, preventing administrators from updating or deleting it through Grafana. The impact is limited to the same organization, with no data exposure reported.
CVSS v3.1
Score 5.4medium
Affected software
Grafana
Grafana OSS
Grafana
Grafana Enterprise
pkg:github/grafana/grafanaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-13720) affects Grafana OSS versions from 12.0.0 up to but not including 13.2.3 in various subversions. An Editor role can set specific file-provisioning metadata annotations (grafana.app/managedBy, grafana.app/managerId, and grafana.app/sourcePath) when creating dashboards through the dashboard API. Because these fields are stored without an authorization check, the dashboard is marked as file-provisioned, which restricts administrators from modifying or deleting it via the Grafana interface. The flaw does not expose data and is scoped to the same organization.
Potential Impact
The vulnerability allows an Editor user to create dashboards that administrators cannot update or delete, potentially causing management and operational issues within the affected organization. There is no data confidentiality impact, but integrity and availability are affected to a limited extent within the same organizational boundary.
Mitigation Recommendations
No explicit patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should review Editor permissions and monitor dashboard provisioning activities to mitigate potential misuse.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GRAFANA
- Date Reserved
- 2026-06-29T14:11:02.739Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abceec30df196e1a9ed5f9a
Added to database: 09/30/2026, 11:13:07 UTC
Last enriched: 09/30/2026, 11:27:14 UTC
Last updated: 09/30/2026, 11:33:15 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.