Grafana Labs · Grafana
CVE-2026-33377
CVE-2026-33377 Grafana dashboard import ACL overwrite
OVERVIEW
Lab observed
Vendor reported
Vendor-reported fixed versions
11.6.14+security-04 / 12.2.8+security-04 / 12.3.6+security-04 / 12.4.3+security-02 / 13.0.1+security-01Only the lab versions above were independently reproduced by CVE Mapping.
LAB OBSERVED
What this lab demonstrates
The synthetic Editor gained dashboard-scoped Admin on 12.4.2; the same logical action retained Edit on 12.4.3+security-02.
The vulnerable and patched modes used equivalent controlled actions. Application state—not a successful HTTP status alone—is decisive.
VULNERABLE VS PATCHED RESULT
Runtime accepted and the documented state difference was observed.
Runtime accepted and the expected safe state was retained.
Evidence, telemetry, and detection checks are recorded in the manifest.
DETECTION COVERAGE
Detection engineering
- Sigma1 lab-validated analytic; 1 experimental contextual analytic
- Splunk1 lab-validated analytic; 1 experimental contextual analytic
- Elastic1 lab-validated analytic; 1 experimental contextual analytic
Grafana router logs provide request context, but the dashboard permission transition is not present in a single router event. The strongest analytic requires correlated authorization-state snapshots; the import request alone does not prove exploitation.
Lab queries
Sigma — grafana_dashboard_permission_escalation.yml lab-validated
title: Grafana Dashboard Permission Escalation for Editor
id: c48841a8-92a5-44d7-8cfa-692aedc36476
status: test
description: Detects a normalized dashboard authorization transition from Edit to Admin while organization role remains Editor and server Admin remains false.
references:
- https://grafana.com/security/security-advisories/cve-2026-33377/
author: CVE Mapping
date: "2026-08-26"
logsource:
product: grafana
service: normalized_authorization_state
detection:
selection:
event_type: authorization_state
dashboard_permission_before: Edit
dashboard_permission_after: Admin
org_role: Editor
server_admin: false
condition: selection
falsepositives:
- Legitimate dashboard permission administration represented without sufficient actor or change-control context
level: high
Sigma — grafana_dashboard_import_editor_context.yml lab-validated
title: Grafana Dashboard Import Request Context
id: f729f8c8-4a85-4b2f-aa9c-a80ec1e72bb6
status: experimental
description: Identifies Grafana dashboard import requests for investigation context; this request occurs in both vulnerable and patched fixtures and does not prove escalation.
references:
- https://grafana.com/security/security-advisories/cve-2026-33377/
author: CVE Mapping
date: "2026-08-26"
logsource:
product: grafana
service: normalized_http_request
detection:
selection:
event_type: http_request
method: POST
path: /api/dashboards/import
condition: selection
falsepositives:
- Authorized dashboard imports and migrations
level: low
Splunk — grafana_dashboard_permission_escalation.spl lab-validated
/*
CVE-2026-33377 normalized authorization-state analytic.
Map local fields before deployment.
*/
event_type="authorization_state" dashboard_permission_before="Edit" dashboard_permission_after="Admin" org_role="Editor" server_admin=false
| eval analytic="grafana_dashboard_permission_escalation"
Splunk — grafana_dashboard_import_editor_context.spl lab-validated
/*
CVE-2026-33377 contextual request analytic.
Non-discriminating between vulnerable and patched fixtures.
*/
event_type="http_request" method="POST" path="/api/dashboards/import"
| eval analytic="grafana_dashboard_import_editor_context"
Elastic — grafana_dashboard_permission_escalation.json lab-validated
{
"name": "Grafana dashboard permission escalation for Editor",
"cve": "CVE-2026-33377",
"type": "query",
"language": "kuery",
"query": "event_type:authorization_state and dashboard_permission_before:Edit and dashboard_permission_after:Admin and org_role:Editor and server_admin:false",
"severity": "high",
"risk_rationale": "The normalized event represents a dashboard-scoped Edit-to-Admin transition while broader roles remain unchanged.",
"false_positive_note": "Validate approved dashboard permission administration and correlation ordering.",
"references": ["https://grafana.com/security/security-advisories/cve-2026-33377/"],
"fixture_discrimination": {"vulnerable": 1, "patched": 0, "benign": 0}
}
Elastic — grafana_dashboard_import_editor_context.json lab-validated
{
"name": "Grafana dashboard import request context",
"cve": "CVE-2026-33377",
"type": "query",
"language": "kuery",
"query": "event_type:http_request and method:POST and path:\"/api/dashboards/import\"",
"severity": "low",
"risk_rationale": "The import route provides investigation context but is not vulnerability-discriminating.",
"false_positive_note": "Authorized dashboard imports and migrations are expected matches.",
"references": ["https://grafana.com/security/security-advisories/cve-2026-33377/"],
"fixture_discrimination": {"vulnerable": 1, "patched": 1, "benign": 0}
}
FIXTURE DISCRIMINATION
Lab fixture performance
Validated state-change analytics matched vulnerable activity and did not match patched or benign controls. Contextual analytics are reported separately and are not promoted to vulnerability discriminators.
EVIDENCE & TELEMETRY
Preserved and verifiable
Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.
RISK CONTEXT
Vendor enrichment
CVSS 7.1 · Vendor-reported · observed 2026-08-26
Additional risk feeds are omitted without a verified current lookup.
MITRE ATT&CK
Unassigned
COPYABLE RUNBOOK
Start with the Quickstart.
Disposable, localhost-only runbook commands taken from the lab's QUICKSTART.md. Proof internals stay in the repository — these are the operator workflow commands.
Validate and prepare
../shared/scripts/lab.sh preflight
../shared/scripts/lab.sh prepareVulnerable mode
../shared/scripts/lab.sh up vulnerable
../shared/scripts/lab.sh wait vulnerable
../shared/scripts/lab.sh init-baseline vulnerable
../shared/scripts/lab.sh init-prereqs vulnerable
../shared/scripts/lab.sh check-33377-prereqs vulnerable
../shared/scripts/lab.sh reproduce-33377 vulnerable
python3 scripts/verify.py verify-mode vulnerable
../shared/scripts/lab.sh down vulnerable
../shared/scripts/lab.sh clean vulnerable --yesPatched control
../shared/scripts/lab.sh up patched
../shared/scripts/lab.sh wait patched
../shared/scripts/lab.sh init-baseline patched
../shared/scripts/lab.sh init-prereqs patched
../shared/scripts/lab.sh check-33377-prereqs patched
../shared/scripts/lab.sh reproduce-33377 patched
python3 scripts/verify.py verify-mode patched
../shared/scripts/lab.sh down patched
../shared/scripts/lab.sh clean patched --yesInspect and validate
python3 scripts/validate-grafana-33377.py --all
python3 scripts/validate-grafana-33377-detections.py --all
python3 labs/grafana/CVE-2026-33377/scripts/build-telemetry.py --check
python3 scripts/verify-integrity.py --allLIMITATIONS & SAFETY
Scope stays explicit.
The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and a bounded controlled proof.