GPU VulnDB

Database/Control plane, storage & DevOps

Grafana: org admin can delete other organizations' snapshots and recover delete keys from share keys

CVE-2026-19197Control plane, storage & DevOpscurated

Impact

Grafana is usually the shared observability plane for a whole fleet, with separate organizations used to keep customer or team dashboards apart. An organization administrator can delete dashboard snapshots that belong to a different organization on the same instance, and can derive a snapshot's secret delete key from nothing more than its public share key. That is a cross-tenant integrity and availability problem inside a tool many operators treat as tenant-isolated: one tenant's admin can destroy another's saved snapshots, and anyone holding a share link gains the delete capability that link was not supposed to carry. No metrics ingestion or dashboard data beyond snapshots is implicated by the advisory.

Who can reach it

An authenticated user with organization administrator permissions on any organization of the shared Grafana instance, over the network. The delete-key recovery additionally needs only a snapshot's public share key, which is by design widely shareable.

What to do

Upgrade to a fixed Grafana OSS or Enterprise release as listed in the vendor security advisory - the record does not name the fixed versions, so read the advisory before scheduling. This is a package or container upgrade plus a restart of grafana-server; no node drain. Grafana Cloud is handled by the vendor.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.