An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | |
| Title | Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-05-13T19:35:08.443Z
Reserved: 2026-03-19T07:55:06.977Z
Link: CVE-2026-33377
No data.
Status : Received
Published: 2026-05-13T20:16:20.470
Modified: 2026-05-13T20:16:20.470
Link: CVE-2026-33377
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.