PatchSiren

Grafana Labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Grafana Labs CVE published 2026-08-10

CVE-2026-72585

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:31.510Z and has not been modified since then. CVE-2026-72585 is an authorization bypass vulnerability in Grafana through 13.2.0. An Editor-role user can delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission. This issue has [truncated]

Known exploited Grafana Labs CVE published 2025-10-09

CVE-2021-43798

CVE-2021-43798 is a Grafana path traversal vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. Because CISA has marked it as known exploited, Grafana deployments should be treated as urgent remediation candidates, especially where instances are reachable by many users or exposed to the internet.

Known exploited Grafana Labs CVE published 2022-08-25

CVE-2021-39226

CVE-2021-39226 is a Grafana authentication bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-08-25, with remediation due by 2022-09-15. Grafana’s vendor advisory notes a critical security fix was released for Grafana 7.5.11 and 8.1.6 on 2021-10-05. Because this issue is listed as known exploited, organizations running Grafana should treat patching and version veri [truncated]