CVE-2026-21724

MEDIUM5.4EPSS 0.02%

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

發布日:2026/3/26修改日:2026/4/23
也稱為:GHSA-7g92-g4vh-hp84BIT-grafana-2026-21724CGA-72xh-mq7m-f2g4

描述

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission. A patched version is available at https://github.com/grafana/grafana/releases/tag/v12.3.6.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

參考連結(5)