CVE-2026-13720

CVE-2026-13720 published: An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The ...

View full NVD advisory → ← Back to CVE watch