Grafana Labs 11.2.0 <= 11.6.16 / 12.2.0 <= 12.2.10 / 12.3.0 <= 12.3.8 / 12.4.0 <= 12.4.5 / 13.0.0 <= 13.0.3 / 13.1.0 < 13.1.1 Information Disclosure (CVE-2026-11817)

medium Nessus Plugin ID 338327

Synopsis

The remote host is affected by an information disclosure vulnerability.

Description

The version of Grafana Labs installed on the remote host is 11.2.x through 11.6.x prior or equal to 11.6.16, 12.2.x prior or equal to 12.2.10, 12.3.x prior or equal to 12.3.8, 12.4.x prior or equal to 12.4.5, 13.0.x prior or equal to 13.0.3, or 13.1.0. It is, therefore, affected by an information disclosure vulnerability:

- This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only. (CVE-2026-11817)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Grafana 13.1.1 or later.

See Also

https://grafana.com/security/security-advisories/cve-2026-11817

Plugin Details

Severity: Medium

ID: 338327

File Name: grafana_CVE-2026-11817.nasl

Version: 1.1

Type: Remote

Family: Web Servers

Published: 8/20/2026

Updated: 8/20/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2026-11817

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/a:grafana:grafana

Required KB Items: Settings/ParanoidReport, installed_sw/Grafana Labs

Patch Publication Date: 7/21/2026

Vulnerability Publication Date: 7/17/2026

Reference Information

CVE: CVE-2026-11817

CWE: 863