CVE-2026-28374
Moderate
IDOR in Annotations API allows unprivileged users to DELETE annotation
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
Exploit probability
0.2%
Published
May 15, 2026
Required by
Not available
Last source change
May 15, 2026
02 / AFFECTED SOFTWARE
Affected packages
9 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
BIT-grafana-2026-28374
View original source
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
Open Source Vulnerabilities
CVE-2026-28374
View original source
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
05 / REFERENCES