Database/Control plane, storage & DevOps
Grafana: an Editor can mark a dashboard file-provisioned, making it undeletable by admins
Impact
The dashboard API stored the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations without an authorization check, so a user with only Editor rights could create a dashboard that presents itself as file-provisioned. Grafana then refuses to let administrators update or delete it through the UI or API, leaving junk or misleading panels pinned in place until someone intervenes at the database level. For a fleet operator this is an integrity and availability nuisance in the observability layer - fabric, DCGM and job dashboards can be squatted or cluttered by anyone with edit rights. Grafana states the effect is confined to the same organization and that no data is exposed.
Who can reach it
Any authenticated user holding the Editor role in a Grafana organization, through the normal dashboard API. Impact stays inside that organization.
What to do
Upgrade to the patched Grafana OSS or Enterprise release listed in the vendor advisory and restart the Grafana service; the NVD record does not pin the fixed version numbers, so take them from grafana.com. Nothing on the GPU nodes themselves is touched. Existing dashboards carrying unexpected provisioning annotations need cleaning up after the upgrade, since patching does not retroactively unmark them.
References
Related entries
- GitLab EE: missing namespace validation lets a user apply compliance frameworks from namespaces they cannot accessCVE-2026-4398 · GitLab EE self-managed (compliance framework namespace validation)Medium
- LibreNMS: reflected XSS in the Proxmox view runs script in a logged-in monitoring user's sessionCVE-2026-45694 · LibreNMS (Proxmox application view, instance and vmid parameters)Medium
- Strimzi: partial Entity Operator deployments still get both operators' RBAC, over-granting the SACVE-2026-55226 · Strimzi Kafka Operator (Entity Operator ServiceAccount RBAC)Medium
- Jenkins Stapler: form binding writes public static fields, applying changes instance-wideCVE-2026-84654 · Jenkins Stapler (form data binding to public static fields)Medium
- Jenkins Pipeline: Build Step Plugin: downstream builds cancelled without Item/Cancel permission checkCVE-2026-84660 · Jenkins Pipeline: Build Step Plugin (build and waitForBuild step cancellation)Medium
- Jenkins Pipeline: Groovy Libraries plugin: CSRF lets an unauthenticated attacker delete library cachesCVE-2026-84663 · Jenkins Pipeline: Groovy Libraries Plugin (shared library cache deletion endpoint)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.