GPU VulnDB

Database/Control plane, storage & DevOps

Grafana: an Editor can mark a dashboard file-provisioned, making it undeletable by admins

CVSS 5.4CVE-2026-13720Control plane, storage & DevOpscurated

Impact

The dashboard API stored the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations without an authorization check, so a user with only Editor rights could create a dashboard that presents itself as file-provisioned. Grafana then refuses to let administrators update or delete it through the UI or API, leaving junk or misleading panels pinned in place until someone intervenes at the database level. For a fleet operator this is an integrity and availability nuisance in the observability layer - fabric, DCGM and job dashboards can be squatted or cluttered by anyone with edit rights. Grafana states the effect is confined to the same organization and that no data is exposed.

Who can reach it

Any authenticated user holding the Editor role in a Grafana organization, through the normal dashboard API. Impact stays inside that organization.

What to do

Upgrade to the patched Grafana OSS or Enterprise release listed in the vendor advisory and restart the Grafana service; the NVD record does not pin the fixed version numbers, so take them from grafana.com. Nothing on the GPU nodes themselves is touched. Existing dashboards carrying unexpected provisioning annotations need cleaning up after the upgrade, since patching does not retroactively unmark them.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.