Database/Control plane, storage & DevOps
Grafana: org admin can delete other organizations' snapshots and recover delete keys from share keys
Impact
Grafana is usually the shared observability plane for a whole fleet, with separate organizations used to keep customer or team dashboards apart. An organization administrator can delete dashboard snapshots that belong to a different organization on the same instance, and can derive a snapshot's secret delete key from nothing more than its public share key. That is a cross-tenant integrity and availability problem inside a tool many operators treat as tenant-isolated: one tenant's admin can destroy another's saved snapshots, and anyone holding a share link gains the delete capability that link was not supposed to carry. No metrics ingestion or dashboard data beyond snapshots is implicated by the advisory.
Who can reach it
An authenticated user with organization administrator permissions on any organization of the shared Grafana instance, over the network. The delete-key recovery additionally needs only a snapshot's public share key, which is by design widely shareable.
What to do
Upgrade to a fixed Grafana OSS or Enterprise release as listed in the vendor security advisory - the record does not name the fixed versions, so read the advisory before scheduling. This is a package or container upgrade plus a restart of grafana-server; no node drain. Grafana Cloud is handled by the vendor.
References
Related entries
- CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching): Stack-based buffer overflow in BIRD's AS_PATH maskCVE-2026-49943 · CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching)Medium
- Prometheus (exporter-toolkit): Poisoning the built-in auth cache bypasses basic-auth on exportersCVE-2022-46146 · Prometheus (exporter-toolkit)Medium
- AMD TEE / ASP bootloader syscall input validation: Insufficient validation of syscall inputs in the AMD trustedCVE-2021-46759 · AMD TEE / ASP bootloader syscall input validationMedium
- HashiCorp Consul: Missing Content-Type header lets user input be reinterpretedCVE-2024-10086 · HashiCorp ConsulMedium
- SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsCVE-2017-5703 · SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsMedium
- Intel Data Center GPU Max Series 1100 / 1550: An improper conditions check lets a privileged local user takeCVE-2023-47165 · Intel Data Center GPU Max Series 1100 / 1550Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.