PT-2026-40791 · Grafana+2 · Grafana+2

CVE-2026-33377

·

Published

2026-05-13

·

Updated

2026-08-24

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:C/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An Editor can overwrite a dashboard they do not own to acquire admin privileges for that specific dashboard. This privilege escalation requires the user to have existing write access to the dashboard.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Authentication

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54178
ALSA-2026:58982
BDU:2026-07034
BIT-GRAFANA-2026-33377
CVE-2026-33377
OPENSUSE-SU-2026:10932-1
OPENSUSE-SU-2026:20940-1
RHSA-2026:54178
SUSE-SU-2026:2768-1
SUSE-SU-2026:2774-1
SUSE-SU-2026:3718-1

Affected Products

Grafana
Red Os
Rocky Linux