CVE-2026-21724
MediumAdvisory
Published 26 Mar 2026In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.4
- base score, highest
- EPSS
- 0.003
- 18th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 18
- of 17,781 indexed, latest versions
- Container images
- 15
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 15 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.0.0-20230830192226-0cfa76b22dd5, v0.0.0-20231011162216-849c612fcb73, v0.0.0-20231218140301-1e84fede543a, v0.0.0-20250812085420-df5de8219b41+dirty+9 more | 1.9.2-0.20260323180334-daffe750de85 | 15 |
- OSV records
- GHSA-7g92-g4vh-hp84GO-2026-5219
- Also known as
- BIT-grafana-2026-21724
Charts affected
18 by stars
Container images carrying it
15 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| grafana/ | 057896e23443 | github.com/ | no fix listed | 2 |
| streamnative/ | 0e6d7aa3ef32 | github.com/ | no fix listed | 2 |
| quay.io/ | 8c65b333a3d3 | github.com/ | no fix listed | 2 |
| bitnamilegacy/ | cb8ab5515676 | github.com/ | no fix listed | 1 |
| grafana/ | 0679e877ba20 | github.com/ | 1.9.2-0.20260323180334-daffe750de85 | 1 |
| grafana/ | 1a359d92f40e | github.com/ | no fix listed | 1 |
| grafana/ | 1b9ca4bbc4a2 | github.com/ | 1.9.2-0.20260323180334-daffe750de85 | 1 |
| grafana/ | 39c849cebccc | github.com/ | no fix listed | 1 |
| grafana/ | 6b5b37eb35bb | github.com/ | 1.9.2-0.20260323180334-daffe750de85 | 1 |
| grafana/ | 76dcf36e7d2a | github.com/ | no fix listed | 1 |
| grafana/ | a1701c218024 | github.com/ | 1.9.2-0.20260323180334-daffe750de85 | 1 |
| grafana/ | 09d8c3ce4f3a | github.com/ | 1.9.2-0.20260323180334-daffe750de85 | 1 |
| svtechnmaa/ | 1d71314424aa | github.com/ | no fix listed | 1 |
| ghcr.io/ | 8de11e2363fc | github.com/ | no fix listed | 1 |
| public.ecr.aws/ | ee9d973e3952 | github.com/ | no fix listed | 1 |