Grafana Paused Dashboard Auth Bypass via Unrevoked Access Token - CVE-2026-81841
CVE-2026-81841 Published on September 29, 2026
Paused shared dashboard access tokens still expose data source configuration
Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-81841 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-81841
Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.
Affected Versions
Grafana Enterprise:- Version 11.6.0, <= 11.6.17 is affected.
- Version 12.0.0, <= 12.0.10 is affected.
- Version 12.1.0, <= 12.1.10 is affected.
- Version 12.2.0, <= 12.2.11 is affected.
- Version 12.3.0, <= 12.3.11 is affected.
- Version 12.4.0 and below 12.4.12 is affected.
- Version 13.0.0 and below 13.0.10 is affected.
- Version 13.1.0 and below 13.1.7 is affected.
- Version 13.2.0 and below 13.2.3 is affected.
- Version 11.6.0, <= 11.6.17 is affected.
- Version 12.0.0, <= 12.0.10 is affected.
- Version 12.1.0, <= 12.1.10 is affected.
- Version 12.2.0, <= 12.2.11 is affected.
- Version 12.3.0, <= 12.3.11 is affected.
- Version 12.4.0 and below 12.4.12 is affected.
- Version 13.0.0 and below 13.0.10 is affected.
- Version 13.1.0 and below 13.1.7 is affected.
- Version 13.2.0 and below 13.2.3 is affected.