Grafana Labs < 11.6.14+security-04 / 12.2.0 < 12.2.8+security-04 / 12.3.0 < 12.3.6+security-04 / 12.4.0 < 12.4.3+security-02 / 13.0.0 < 13.0.1+security-01 Multiple Vulnerabilities

high Nessus Plugin ID 316482

Synopsis

The remote host is missing a security update.

Description

The version of Grafana Labs installed on the remote host is affected by multiple vulnerabilities, including:
- A broken access control flaw in the Snapshot API allows any Editor to delete dashboard snapshots, even those they have no read or write access to. (CVE-2026-28380)

- When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses, allowing the intended whitelist to be bypassed. (CVE-2026-33376)

- Dashboard import overwrites the dashboard ACL, allowing an Editor to overwrite a dashboard not owned by them and acquire admin on that specific dashboard. (CVE-2026-33377)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update Grafana Labs to 11.6.14+security-04, 12.2.8+security-04, 12.3.6+security-04, 12.4.3+security-02, 13.0.1+security-01 or later.

See Also

http://www.nessus.org/u?422499b2

http://www.nessus.org/u?efa9acae

http://www.nessus.org/u?afc20dc5

http://www.nessus.org/u?3f991c78

http://www.nessus.org/u?b0568e82

http://www.nessus.org/u?621b46b4

http://www.nessus.org/u?8b7b1484

http://www.nessus.org/u?b54f491c

http://www.nessus.org/u?10329fa6

http://www.nessus.org/u?4dd6a359

Plugin Details

Severity: High

ID: 316482

File Name: grafana_13_0_1_01.nasl

Version: 1.1

Type: Remote

Family: Web Servers

Published: 5/22/2026

Updated: 5/22/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:C/A:N

CVSS Score Source: CVE-2026-33377

CVSS v3

Risk Factor: High

Base Score: 7.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS Score Source: CVE-2026-33376

Vulnerability Information

CPE: cpe:/a:grafana:grafana

Required KB Items: installed_sw/Grafana Labs

Patch Publication Date: 5/13/2026

Vulnerability Publication Date: 5/13/2026

Reference Information

CVE: CVE-2026-28374, CVE-2026-28376, CVE-2026-28379, CVE-2026-28380, CVE-2026-28383, CVE-2026-33376, CVE-2026-33377, CVE-2026-33378, CVE-2026-33380, CVE-2026-33381

IAVB: 2026-B-0128