Intel

AIKIDO-2025-10269

Grafana is vulnerable to Improper Access Control

Improper Access ControlCVE-2025-3260 Published Apr 25, 2025

83

High Risk

This Affects:

osGrafana
11.6.0 - 11.6.0
Fixed in 11.6.1
Are you affected? Scan for Free

TL;DR

During the development of a new feature in Grafana 11.6.x, a security vulnerability was introduced that allows for Viewers and Editors to bypass dashboard-specific permissions. As a result, users with the Viewer role could view all the dashboards within their org and users with the Editor role could view, edit, and delete all the dashboards in their org.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Grafana is vulnerable to Improper Access Control in versions 11.6.0 - 11.6.0.

How to fix this

Upgrade the Grafana library to the patch version.