A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
References
Configurations
No configuration.
History
27 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-285 | |
| Summary |
|
26 Mar 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-26 21:17
Updated : 2026-03-30 13:26
NVD link : CVE-2026-21724
Mitre link : CVE-2026-21724
CVE.ORG link : CVE-2026-21724
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization
