Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-13720— Editor can forge file-provisioning provenance on dashboards via the dashboard API

Quick assessment

Affected
Grafana Grafana OSS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

编辑者(Editor)角色在通过仪表盘 API 创建仪表盘时,可以设置文件配置元数据(即 、 和 注解),因为这些字段在存储时未进行权限检查。这会导致该仪表盘被标记为“文件配置”(file-provisioned),从而使管理员无法再通过 Grafana 界面对其进行更新或删除。该漏洞的影响范围仅限于同一组织内部,且不会导致任何数据泄露。

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-13720

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Editor can forge file-provisioning provenance on dashboards via the dashboard API
Source: CVE Program / CVE List V5
Vulnerability Description
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Grafana Grafana OSS 12.0.0 ~ 12.0.10 -
Grafana Grafana Enterprise 12.0.0 ~ 12.0.10 -

II. Public POCs for CVE-2026-13720

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13720

请登录查看更多情报信息。

Other References for CVE-2026-13720 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-13720

No comments yet


Leave a comment