Grafana: Insecure Deletion of CrossOrg Dashboard Snapshots (CVE202619197)
CVE-2026-19197 Published on August 26, 2026
Broken access control in dashboard snapshots
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-19197 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-19197
Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.
Affected Versions
Grafana OSS:- Version 12.4.0 and below 12.4.8 is affected.
- Version 13.0.0 and below 13.0.6 is affected.
- Version 13.1.0 and below 13.1.3 is affected.
- Version 12.4.0 and below 12.4.8 is affected.
- Version 13.0.0 and below 13.0.6 is affected.
- Version 13.1.0 and below 13.1.3 is affected.