CVE-2026-13720

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-345CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0xdevshm@0xdevshm

    Grafana v13.2.3 is out. - Security: Fix CVE-2026-13719 - Security: Fix CVE-2026-13720 https://github.com/grafana/grafana/releases/tag/v13.2.3 #grafana #release #programming

    0000025
    130 followersView on X

Explore more