CVE-2026-33377General(grafana / grafana)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
grafana

6 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-25: 1Mentions · 2026-08-13: 1Technical Details · 2026-05-13: 105-1305-2508-13
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-131
Disclosure1
2026-05-251
General1
2026-08-131
General1
Full discourse3 posts
  • Autumn Good@autumn_good_35
    General

    Severity: CRITICAL Traefik Authentication Middleware Header Handling Vulnerability (CVE-2026-54763) Grafana Dashboard Privilege Escalation Vulnerability (CVE-2026-33377) Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core https://csaf.arubanetworking.hpe.com/2026/hpe_aruba_networking_-_hpesbnw05119.txt

    Post summary

    The post lists critical CVEs and refers to a CSAF advisory but provides no detailed technical, exploit, or patch information.

    00011629
    7.0K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Grafana ❗ CVE-2026-33377 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-grafana-4/ https://t.co/F7I9DnoyvP

    Post summary

    The tweet alerts about a Grafana vulnerability (CVE-2026-33377) and points to external sources, but provides no additional technical or exploit information.

    00010122
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33377 An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privil… https://www.cve.org/CVERecord?id=CVE-2026-33377

    Post summary

    The post discloses a privilege escalation vulnerability (CVE‑2026‑33377) where an editor can overwrite another user’s dashboard to gain admin rights, provided they have write access.

    00000136
    57.5K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---
Appgrafanagrafana11.6.14--
Appgrafanagrafana11.6.14--
Appgrafanagrafana12.2.8--
Appgrafanagrafana12.2.8--
Appgrafanagrafana12.3.6--
Appgrafanagrafana12.3.6--
Appgrafanagrafana12.4.3--
Appgrafanagrafana13.0.0--
Appgrafanagrafana13.0.1--

Explore more