CVE-2026-21724

medium

Description

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

References

https://github.com/Nel-droid/CVE-2026-72585-PoC

https://grafana.com/security/security-advisories/cve-2026-21724

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16338

Details

Source: Mitre, NVD

Published: 2026-03-26

Updated: 2026-04-14

Named Vulnerability: GO-2026-5219Named Vulnerability: GHSA-7g92-g4vh-hp84

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00027