CVE-2026-21722Disclosure(grafana / grafana)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-12)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
grafana

4 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-12: 2PoC Mentioned / Linked · 2026-02-11: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 202-1102-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-122
Disclosure2
Full discourse3 posts
  • spaceraccoon | Eugene Lim@spaceraccoonsec
    Disclosure

    Vulnerability-spoiler-alert has detected its first two live “negative-days” in Grafana! CVE-2025-41117 (XSS) and CVE-2026-21722 (Privesc) are still unpublished right now, but is detectable via commits in the open-source repo. That’s at least 1 hour early. PoCs and more at https://vulnerabilityspoileralert.com

    Post summary

    The post announces the early detection of two unpublished Grafana vulnerabilities—an XSS and a privilege‑escalation flaw—providing a link to PoCs but no evidence of active exploitation or patches.

    02602039211.6K
    25.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21722 Annotation Timerange Bypass in Public Dashboards with Annotations Enabled https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21722

    Post summary

    CVE-2026-21722 discloses a timerange bypass vulnerability affecting public dashboards when annotations are enabled, without mention of exploitation, patches, or PoC details.

    0001029
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21722 Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the ent… https://www.cve.org/CVERecord?id=CVE-2026-21722

    Post summary

    CVE-2026-21722 highlights a configuration flaw in public dashboards that permits unrestricted access to annotation timeranges, potentially exposing sensitive data, with no PoC, exploit, or patch information provided.

    00010409
    56.5K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---
Appgrafanagrafana11.6.10--
Appgrafanagrafana12.1.6--
Appgrafanagrafana12.2.4--
Appgrafanagrafana12.3.2--

Explore more