Grafana is vulnerable to Improper Access Control
83
High Risk
During the development of a new feature in Grafana 11.6.x, a security vulnerability was introduced that allows for Viewers and Editors to bypass dashboard-specific permissions. As a result, users with the Viewer role could view all the dashboards within their org and users with the Editor role could view, edit, and delete all the dashboards in their org.
You are affected if you are using a version that falls within the vulnerable range.
Grafana is vulnerable to Improper Access Control in versions 11.6.0 - 11.6.0.
Upgrade the Grafana library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant