CVE-2026-28380
Moderate
BAC in Snapshot API allows deletion of unauthorized dashboard snapshots
Any Editor could delete any snapshot, even if they have no access to read or write them.
Exploit probability
0.2%
Published
May 15, 2026
Required by
Not available
Last source change
May 15, 2026
02 / AFFECTED SOFTWARE
Affected packages
9 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
BIT-grafana-2026-28380
View original source
Any Editor could delete any snapshot, even if they have no access to read or write them.
Open Source Vulnerabilities
CVE-2026-28380
View original source
Any Editor could delete any snapshot, even if they have no access to read or write them.
05 / REFERENCES