Grafana Dashboard API Allows Unauthorized FileProvisioning Metadata Injection
CVE-2026-13720 Published on September 30, 2026
Editor can forge file-provisioning provenance on dashboards via the dashboard API
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
Weakness Types
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-13720 has been classified to as an AuthZ vulnerability or weakness.
What is a Mass Assignment Vulnerability?
The software receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CVE-2026-13720 has been classified to as a Mass Assignment vulnerability or weakness.
Insufficient Verification of Data Authenticity
The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Products Associated with CVE-2026-13720
Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.
Affected Versions
Grafana OSS:- Version 12.0.0, <= 12.0.10 is affected.
- Version 12.1.0, <= 12.1.10 is affected.
- Version 12.2.0, <= 12.2.11 is affected.
- Version 12.3.0, <= 12.3.11 is affected.
- Version 12.4.0 and below 12.4.12 is affected.
- Version 13.0.0 and below 13.0.10 is affected.
- Version 13.1.0 and below 13.1.7 is affected.
- Version 13.2.0 and below 13.2.3 is affected.
- Version 12.0.0, <= 12.0.10 is affected.
- Version 12.1.0, <= 12.1.10 is affected.
- Version 12.2.0, <= 12.2.11 is affected.
- Version 12.3.0, <= 12.3.11 is affected.
- Version 12.4.0 and below 12.4.12 is affected.
- Version 13.0.0 and below 13.0.10 is affected.
- Version 13.1.0 and below 13.1.7 is affected.
- Version 13.2.0 and below 13.2.3 is affected.