CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
Configurations

No configuration.

History

27 Mar 2026, 15:16

Type Values Removed Values Added
CWE CWE-285
Summary
  • (es) Se ha descubierto una vulnerabilidad en Grafana OSS donde una omisión de autorización en la API de puntos de contacto de aprovisionamiento permite a los usuarios con rol de Editor modificar URLs de webhook protegidas sin el permiso requerido alert.notifications.receivers.protected:write.

26 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 21:17

Updated : 2026-03-30 13:26


NVD link : CVE-2026-21724

Mitre link : CVE-2026-21724

CVE.ORG link : CVE-2026-21724


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization