PT-2026-8220 · Grafana+1 · Grafana+1

CVE-2026-21727

·

Published

2026-01-29

·

Updated

2026-08-19

CVSS v2.0

3.6

Low

VectorAV:N/AC:H/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 11.6.11, 12.0.9, 12.1.6, and 12.2.4
Description A cross-tenant isolation issue exists in the Correlations feature affecting legacy correlation records. A backward compatibility condition allows records where org id = 0 to be returned across different organizations. Consequently, a user with datasource management privileges can read and permanently delete legacy correlation data belonging to another organization.
Recommendations Update to version 11.6.11 or later. Update to version 12.0.9 or later. Update to version 12.1.6 or later. Update to version 12.2.4 or later.

Exploit

Fix

DoS

Incorrect Permission

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02013
BIT-GRAFANA-2026-21727
CVE-2026-21727

Affected Products

Grafana
Red Os