Description

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

INFO

Published Date :

2026-02-12T08:49:05.678Z

Last Modified :

2026-04-09T13:49:26.286Z

Source :

GRAFANA
AFFECTED PRODUCTS

The following products are affected by CVE-2026-21722 vulnerability.

Vendors Products
Grafana
  • Grafana
  • Grafana Enterprise

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact