Security Advisory

CVE-2026-21724

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-26 20:06:18
Last updated 2026-07-29 14:00:25
Assigner GRAFANA
CVSS score 5.4
State PUBLISHED

Description

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.