« Volver al listado

CVE-2026-21724

Estado: AnalizadaMedia (4.3)—

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-21724",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-21724",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-27T13:42:43.732342Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@grafana.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@grafana.com",
      "affectedData": [
        {
          "vendor": "Grafana",
          "product": "Grafana OSS",
          "versions": [
            {
              "status": "affected",
              "version": "12.3.1",
              "lessThan": "12.3.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "12.2.2",
              "lessThan": "12.2.8",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "12.1.5",
              "lessThan": "12.1.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.6.9",
              "lessThan": "11.6.14",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-26T21:17:03.227",
  "references": [
    {
      "url": "https://grafana.com/security/security-advisories/cve-2026-21724",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@grafana.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto una vulnerabilidad en Grafana OSS donde una omisión de autorización en la API de puntos de contacto de aprovisionamiento permite a los usuarios con rol de Editor modificar URLs de webhook protegidas sin el permiso requerido alert.notifications.receivers.protected:write."
    }
  ],
  "lastModified": "2026-06-17T13:20:05.397",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B333C05C-D6CC-4292-B54B-5D081FE92C6E",
              "versionEndExcluding": "11.6.14",
              "versionStartIncluding": "11.6.9"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "252E74A8-BC0A-420D-A937-84AAE46C8BDA",
              "versionEndExcluding": "12.1.10",
              "versionStartIncluding": "12.1.5"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "409163A6-7B0A-4E46-AD47-620AFC841A9B",
              "versionEndExcluding": "12.2.8",
              "versionStartIncluding": "12.2.2"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "875BA099-9D0F-4DC0-80DF-5F35D06097AC",
              "versionEndExcluding": "12.3.6",
              "versionStartIncluding": "12.3.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@grafana.com"
}