A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
References
| Link | Resource |
|---|---|
| https://grafana.com/security/security-advisories/cve-2026-21724 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Apr 2026, 01:00
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://grafana.com/security/security-advisories/cve-2026-21724 - Vendor Advisory | |
| CPE | cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* | |
| First Time |
Grafana
Grafana grafana |
27 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-285 | |
| Summary |
|
26 Mar 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-26 21:17
Updated : 2026-04-14 01:00
NVD link : CVE-2026-21724
Mitre link : CVE-2026-21724
CVE.ORG link : CVE-2026-21724
JSON object : View
Products Affected
grafana
- grafana
CWE
CWE-285
Improper Authorization
