CVE-2026-19197
MEDIUM
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Aug 26, 2026
Vendor
unknown
Description
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).