SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-21722

This did not leak any annotations that would not otherwise be visible on the public dashboard.

MEDIUM 5.3EPSS 0.33%

Does this matter?

Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.

Description

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.33% probability · 26th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-863
Affected
grafana/grafana
Source
security@grafana.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.