Grafana Paused Dashboard Auth Bypass via Unrevoked Access Token - CVE-2026-81841
CVE-2026-81841 Published on September 29, 2026

Paused shared dashboard access tokens still expose data source configuration
Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.

Vendor Advisory NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-81841 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-81841

Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.

 

Affected Versions

Grafana Enterprise: Grafana OSS: