Grafana <=13.2.0 Editor Bypass Deleting Protected Contact Points
CVE-2026-72585 Published on August 10, 2026
Grafana - Incomplete Fix for CVE-2026-21724 Allows Editor Role to Delete Protected Contact Points
An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.
Vulnerability Analysis
CVE-2026-72585 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Timeline
CVE Reserved
Public Disclosure
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-72585 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-72585
Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.
Affected Versions
Grafana Labs Grafana:- Before and including 13.2.0 is affected.