Grafana: Insecure Deletion of CrossOrg Dashboard Snapshots (CVE202619197)
CVE-2026-19197 Published on August 26, 2026

Broken access control in dashboard snapshots
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).

Vendor Advisory NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-19197 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-19197

Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.

 

Affected Versions

Grafana OSS: Grafana Enterprise: