A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-33381

CVE-2026-33381: Service Account Auth Bypass Vulnerability

CVE-2026-33381 is an authorization bypass flaw in service account token minting that allows revoked users to retain access for several seconds. This article covers the technical details, impact, and mitigation strategies.

Published: May 14, 2026

CVE-2026-33381 Overview

CVE-2026-33381 is a race condition vulnerability in Grafana that affects the revocation of service account token minting permissions. When an administrator revokes a user's access to mint tokens for a service account, the user retains the ability to perform this action for a brief window after the revocation event. The access is eventually removed, but the delay creates an exploitable window for privileged users.

The issue is documented in the Grafana Security Advisory. The vulnerability requires high privileges and high attack complexity, limiting the population of attackers who can exploit it.

Critical Impact

A user whose token-minting access was revoked can still mint service account tokens during a short post-revocation window, enabling continued access to resources tied to the service account.

Affected Products

  • Grafana (refer to vendor advisory for affected version ranges)
  • Deployments using service account token minting workflows
  • Multi-tenant Grafana environments with privileged user role changes

Discovery Timeline

  • 2026-05-13 - CVE-2026-33381 published to NVD
  • 2026-05-13 - Last updated in NVD database

Technical Details for CVE-2026-33381

Vulnerability Analysis

The vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition affecting service account token minting in Grafana. Service accounts in Grafana represent non-human identities used to authenticate API calls and automation workflows. Minting a token for a service account produces credentials that act on behalf of that identity.

When an administrator revokes a user's permission to mint tokens, the authorization state change does not propagate immediately to every code path that evaluates the permission. During the propagation delay, the user can still issue valid token minting requests. The window is measured in seconds, but it is sufficient for an automated client to issue one or more requests after revocation has nominally occurred.

The vulnerability affects confidentiality and integrity because the resulting tokens can read and modify resources tied to the service account. Availability is not directly impacted.

Root Cause

The root cause is delayed permission propagation in Grafana's authorization layer. The system caches or asynchronously updates the access decision used by the token minting endpoint. Until the cache is refreshed or the change replicates, the previous authorization state remains effective for that user.

Attack Vector

An attacker must already hold high privileges in Grafana and must time requests to coincide with the revocation event. The attack is network-based and does not require user interaction. A malicious or compromised user, anticipating revocation, can script repeated token minting calls and capture any tokens issued during the propagation window. Those tokens then provide persistent access until they are independently revoked or expire.

Detection Methods for CVE-2026-33381

Indicators of Compromise

  • Service account tokens created within seconds after a permission revocation event for the requesting user.
  • Audit log entries showing successful serviceaccounts:write or token creation actions performed by users whose roles were just changed.
  • Use of service account tokens that were minted by a user no longer authorized to mint them.

Detection Strategies

  • Correlate Grafana audit logs for permission revocation events against subsequent token creation events from the same actor within a short time window.
  • Alert on any token minting activity that occurs after a RolePermissionRemoved or equivalent administrative action targeting the same actor.
  • Review service account token inventories for tokens whose creator lacked minting permissions at the time of token use.

Monitoring Recommendations

  • Forward Grafana audit logs to a centralized logging platform and retain them for forensic review.
  • Track service account token creation rates per user and alert on bursts that coincide with role changes.
  • Periodically reconcile active tokens against current user permissions and flag mismatches.

How to Mitigate CVE-2026-33381

Immediate Actions Required

  • Apply the Grafana patch documented in the Grafana Security Advisory.
  • After revoking a user's token minting permission, immediately audit and rotate any service account tokens the user could have created.
  • Restrict service account token minting privileges to a minimal set of administrative accounts.

Patch Information

Grafana has issued a security advisory addressing CVE-2026-33381. Refer to the Grafana Security Advisory for fixed versions and upgrade guidance. Upgrade affected Grafana instances to the patched release before relying on revocation as a control.

Workarounds

  • When revoking token minting access, follow the revocation with immediate rotation of existing service account tokens linked to that scope.
  • Reduce the blast radius by scoping service accounts to least-privilege roles, limiting what a stolen token can do.
  • Consider disabling the affected user account entirely during role transitions, rather than relying solely on permission removal.
bash
# Configuration example: rotate service account tokens after revocation
# Replace SA_ID and TOKEN_ID with values from your Grafana instance
curl -X DELETE \
  -H "Authorization: Bearer $ADMIN_TOKEN" \
  "https://grafana.example.com/api/serviceaccounts/${SA_ID}/tokens/${TOKEN_ID}"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechN/A

  • SeverityMEDIUM

  • CVSS Score5.9

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
  • Impact Assessment
  • ConfidentialityHigh
  • IntegrityNone
  • AvailabilityNone
  • Technical References
  • Grafana Security Advisory
  • Latest CVEs
  • CVE-2024-8261: Prolizyazilim OBS Auth Bypass Vulnerability

  • CVE-2024-13068: LimonDesk Auth Bypass Vulnerability

  • CVE-2025-53679: Fortinet FortiSandbox RCE Vulnerability

  • CVE-2026-9446: Simple POS Inventory System SQLi Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English