Grafana Labs · Grafana
CVE-2026-33377
CVE-2026-33377 Grafana dashboard import ACL overwrite
OVERVIEW
Lab observed
Vendor reported
Vendor-reported fixed versions
11.6.14+security-04 / 12.2.8+security-04 / 12.3.6+security-04 / 12.4.3+security-02 / 13.0.1+security-01Only the lab versions above were independently reproduced by CVE Mapping.
LAB OBSERVED
What this lab demonstrates
The synthetic Editor gained dashboard-scoped Admin on 12.4.2; the same logical action retained Edit on 12.4.3+security-02.
The vulnerable and patched modes used equivalent controlled actions. Application state—not a successful HTTP status alone—is decisive.
VULNERABLE VS PATCHED RESULT
Runtime accepted and the documented state difference was observed.
Runtime accepted and the expected safe state was retained.
Evidence, telemetry, and detection checks are recorded in the manifest.
DETECTION COVERAGE
Detection engineering
- Sigma1 lab-validated analytic; 1 experimental contextual analytic
- Splunk1 lab-validated analytic; 1 experimental contextual analytic
- Elastic1 lab-validated analytic; 1 experimental contextual analytic
Grafana router logs provide request context, but the dashboard permission transition is not present in a single router event. The strongest analytic requires correlated authorization-state snapshots; the import request alone does not prove exploitation.
FIXTURE DISCRIMINATION
Lab fixture performance
Validated state-change analytics matched vulnerable activity and did not match patched or benign controls. Contextual analytics are reported separately and are not promoted to vulnerability discriminators.
EVIDENCE & TELEMETRY
Preserved and verifiable
Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.
RISK CONTEXT
Vendor enrichment
CVSS 7.1 · Vendor-reported · observed 2026-08-26
Additional risk feeds are omitted without a verified current lookup.
MITRE ATT&CK
Unassigned
REPRODUCE LOCALLY
Start with the Quickstart.
Use the repository operator workflow on a disposable, localhost-only environment. The website does not embed proof payload content.
Open QuickstartLIMITATIONS & SAFETY
Scope stays explicit.
The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and a bounded controlled proof.