CVE 5.3 MEDIUM

Public Dashboards time range restriction on annotations can be bypassed_CVE-2026-21722

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.

This did not leak any annotations that would not otherwise be visible on the public dashboard.

Basic Information

ID CVE-2026-21722
Source GRAFANA
Published Feb 12, 2026 at 08:49

Affected Product

Vendor Grafana
Product grafana/grafana
Version 9.3.0
Affected Versions Grafana grafana/grafana 9.3.0
Grafana grafana/grafana 12.0.0
Grafana grafana/grafana 12.2.0
Grafana grafana/grafana 12.3.0
Grafana grafana/grafana-enterprise 9.3.0
Grafana grafana/grafana-enterprise 12.0.0
Grafana grafana/grafana-enterprise 12.2.0
Grafana grafana/grafana-enterprise 12.3.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.