CVE-2026-28378

Updated on 07 Jul 2026

Severity

2.7 Low severity

Details

CVSS score
2.7
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Overview

About vulnerability

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard’s identifiers.

Details

Affected product:
Alpine Linux 3.22 , Debian 12 , Debian 13
Affected packages:
grafana @ 11.4 (+10 more)