PT-2026-8220 · Grafana+1 · Grafana+1
CVE-2026-21727
·
Published
2026-01-29
·
Updated
2026-08-19
CVSS v2.0
3.6
Low
| Vector | AV:N/AC:H/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Grafana versions prior to 11.6.11, 12.0.9, 12.1.6, and 12.2.4
Description
A cross-tenant isolation issue exists in the Correlations feature affecting legacy correlation records. A backward compatibility condition allows records where
org id = 0 to be returned across different organizations. Consequently, a user with datasource management privileges can read and permanently delete legacy correlation data belonging to another organization.Recommendations
Update to version 11.6.11 or later.
Update to version 12.0.9 or later.
Update to version 12.1.6 or later.
Update to version 12.2.4 or later.
Exploit
Fix
DoS
Incorrect Permission
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grafana
Red Os