Database/Control plane, storage & DevOps
Grafana: legacy correlation records can be read and permanently deleted across organizations
Impact
A backward-compatibility path returns correlation records with org_id = 0 to every organization, so a user holding datasource management privileges in one org can read and permanently delete legacy correlation data belonging to another. Where Grafana organizations are the separation between tenants or between teams sharing a fleet observability stack, this is a cross-tenant read plus an irreversible delete - the destroyed records are not recoverable without a restore. Scope is narrow: only correlations created before Grafana 10.2 are affected, and correlations are dashboard link definitions, not the metrics or logs themselves. Grafana rates it 3.3 with high privileges and high attack complexity required.
Who can reach it
An authenticated Grafana user with datasource management privileges in any organization on a shared instance, over the Grafana UI or API. No administrator role on the target organization is needed.
What to do
Upgrade to Grafana 11.6.11, 12.0.9, 12.1.6 or 12.2.4 or later per the vendor advisory. This is a service upgrade and restart - a container image bump or package upgrade with a short observability gap, no node drain and no GPU impact. If legacy correlations matter to you, confirm you have a backup of the Grafana database before upgrading, since the deletion this allows is permanent.
References
Related entries
- RabbitMQ: Unsanitized username rendered in the management UICVE-2021-32718 · RabbitMQLow
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysCVE-2023-32082 · etcdLow
- Prometheus / Thanos (golang-jwt): Unclear ParseWithClaims error behaviorCVE-2024-51744 · Prometheus / Thanos (golang-jwt)Low
- GitLab: a developer removed from a project can still push commits via merge request collaboration settingsCVE-2025-14562 · GitLab CE/EE (merge request collaboration authorization)Low
- Inspektor Gadget: malformed ELF crashes or exhausts memory in the privileged eBPF tracerCVE-2026-44778 · Inspektor Gadget uprobetracer USDT note parser (pkg/uprobetracer/usdt.go)Low
- Jenkins: project naming strategy config lets Overall/Manage holders instantiate admin-only typesCVE-2026-70430 · Jenkins core (project naming strategy configuration)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.