Skip to main content
Vulnerability Database/CVE-2026-13720

CVE-2026-13720: Grafana Dashboard Auth Bypass Vulnerability

CVE-2026-13720 is an authorization bypass flaw in Grafana that lets editors set file-provisioning metadata on dashboards, preventing administrators from managing them. This article covers technical details, impact, and mitigation.

Published:

CVE-2026-13720 Overview

CVE-2026-13720 is a broken access control vulnerability in Grafana that allows an authenticated user with Editor privileges to mark dashboards as file-provisioned. The dashboard API accepts the grafana.app/managedBy, grafana.app/managerId, and grafana.app/sourcePath annotations without performing an authorization check. Once these annotations are set, Grafana treats the dashboard as externally provisioned and blocks administrators from updating or deleting it through the user interface. The impact is scoped to the same organization, and no data is disclosed. The issue is tracked under CWE-285: Improper Authorization.

Critical Impact

An Editor can create dashboards that administrators cannot modify or remove through Grafana, disrupting dashboard lifecycle management within the affected organization.

Affected Products

  • Grafana (dashboard API accepting provisioning annotations)
  • Deployments where Editor role is delegated to non-administrative users
  • Multi-tenant Grafana organizations sharing dashboard workspaces

Discovery Timeline

  • 2026-09-30 - CVE-2026-13720 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-13720

Vulnerability Analysis

Grafana supports file-based provisioning of dashboards, where dashboards imported from disk are marked with reserved annotations. The presence of these annotations tells Grafana that the dashboard is managed externally, so the UI prevents administrators from editing or deleting it. The dashboard API failed to validate whether the caller was authorized to set these provisioning annotations. As a result, any user holding the Editor role can inject the annotations at creation time. The dashboard then appears file-provisioned even though it was created through the API by a low-privileged user.

Root Cause

The root cause is a missing authorization check on the grafana.app/managedBy, grafana.app/managerId, and grafana.app/sourcePath metadata fields. These annotations should be writable only by the provisioning subsystem or by administrators. Grafana stored the values submitted in the API request without enforcing role-based restrictions on the metadata keys.

Attack Vector

An attacker authenticated with Editor privileges submits a dashboard creation request to the Grafana dashboard API. The request body includes the reserved provisioning annotations. Grafana persists the dashboard with those annotations intact. Administrators subsequently see the dashboard as file-provisioned and lose the ability to modify or remove it through the standard UI workflows. The attack requires network access to the Grafana instance and valid Editor credentials within the target organization. See the Grafana Security Advisory CVE-2026-13720 for vendor technical details.

Detection Methods for CVE-2026-13720

Indicators of Compromise

  • Dashboards that appear as file-provisioned but do not correspond to any entry in the Grafana provisioning directory or configuration.
  • Audit log entries showing dashboard creation by non-administrative users where the request payload contains grafana.app/managedBy, grafana.app/managerId, or grafana.app/sourcePath annotations.
  • Administrators reporting that they cannot edit or delete dashboards through the Grafana UI.

Detection Strategies

  • Query the Grafana database or API for dashboards whose provisioning annotations reference source paths that do not exist on the Grafana server filesystem.
  • Correlate dashboard creation events with the identity of the requesting user and flag Editors that set reserved grafana.app/* metadata.
  • Review reverse proxy or API gateway logs for POST requests to the dashboard endpoint containing the reserved annotation keys.

Monitoring Recommendations

  • Enable Grafana audit logging and forward events to a centralized SIEM for correlation with user role assignments.
  • Alert on any dashboard write operation that includes provisioning annotations but originates from an interactive user session rather than the provisioning process.
  • Periodically reconcile the set of file-provisioned dashboards in the database against the on-disk provisioning manifests.

How to Mitigate CVE-2026-13720

Immediate Actions Required

  • Upgrade Grafana to the fixed version documented in the Grafana Security Advisory CVE-2026-13720.
  • Audit existing dashboards for unexpected provisioning annotations and remove or reset them where the source path is not legitimate.
  • Review Editor role assignments and reduce membership to the minimum required set of users.

Patch Information

Grafana Labs has published a security advisory and corresponding patch. Apply the vendor-supplied update as described in the advisory. Refer to the Grafana Security Advisory CVE-2026-13720 for the exact fixed versions and upgrade procedure.

Workarounds

  • Restrict who can hold the Editor role until the patch is applied, favoring the Viewer role for users who do not require write access.
  • Place Grafana behind an API gateway or reverse proxy that strips grafana.app/managedBy, grafana.app/managerId, and grafana.app/sourcePath annotations from inbound dashboard create and update requests.
  • Run scheduled jobs to detect and clear unauthorized provisioning annotations on dashboards that are not backed by on-disk provisioning files.
bash
# Configuration example
# Query dashboards flagged as file-provisioned in the Grafana database
# and review the associated source paths for legitimacy.
SELECT id, uid, title, org_id
FROM dashboard
WHERE data::text LIKE '%grafana.app/managedBy%';

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.