CVE-2026-21721 | Grafana up to 11.6.8/12.0.7/12.1.4/12.2.2/12.3.0 Dashboard Permissions API permission (WID-SEC-2026-0224)
A vulnerability described as critical has been identified in Grafana up to 11.6.8/12.0.7/12.1.4/12.2.2/12.3.0. Affected by this issue is some unknown functionality of the component Dashboard Permissions API. Executing a manipulation can lead to permission issues.
This vulnerability is registered as CVE-2026-21721. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.