<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:10:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-06002</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06002</link>
      <description>bdu:2025-06002</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06002</guid>
    </item>
    <item>
      <title>BIT-grafana-2025-3580</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2025-3580</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited when:&lt;/p&gt;
&lt;p&gt;1. An Organization administrator exists&lt;/p&gt;
&lt;p&gt;2. The Server administrator is either:&lt;/p&gt;
&lt;p&gt;- Not part of any organization, or
   - Part of the same organization as the Organization administrator
Impact:&lt;/p&gt;
&lt;p&gt;- Organization administrators can permanently delete Server administrator accounts&lt;/p&gt;
&lt;p&gt;- If the only Server administrator is deleted, the Grafana instance becomes unmanageable&lt;/p&gt;
&lt;p&gt;- No super-user permissions remain in the system&lt;/p&gt;
&lt;p&gt;- Affects all users, organizations, and teams managed in the instance&lt;/p&gt;
&lt;p&gt;The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited when:&lt;/p&gt;
&lt;p&gt;1. An Organization administrator exists&lt;/p&gt;
&lt;p&gt;2. The Server administrator is either:&lt;/p&gt;
&lt;p&gt;- Not part of any organization, or
   - Part of the same organization as the Organization administrator
Impact:&lt;/p&gt;
&lt;p&gt;- Organization administrators can permanently delete Server administrator accounts&lt;/p&gt;
&lt;p&gt;- If the only Server administrator is deleted, the Grafana instance becomes unmanageable&lt;/p&gt;
&lt;p&gt;- No super-user permissions remain in the system&lt;/p&gt;
&lt;p&gt;- Affects all users, organizations, and teams managed in the instance&lt;/p&gt;
&lt;p&gt;The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2025-3580</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0447 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles permettent à un attaquant de provoquer une atteinte…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0447</link>
      <description>certfr-2025-avi-0447</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0447</guid>
    </item>
    <item>
      <title>EUVD-2026-247763</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-247763</link>
      <description>EUVD-2026-247763</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-247763</guid>
    </item>
    <item>
      <title>fkie_cve-2025-3580</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3580</link>
      <description>&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited when:&lt;/p&gt;
&lt;p&gt;1. An Organization administrator exists&lt;/p&gt;
&lt;p&gt;2. The Server administrator is either:&lt;/p&gt;
&lt;p&gt;- Not part of any organization, or
   - Part of the same organization as the Organization administrator
Impact:&lt;/p&gt;
&lt;p&gt;- Organization administrators can permanently delete Server administrator accounts&lt;/p&gt;
&lt;p&gt;- If the only Server administrator is deleted, the Grafana instance becomes unmanageable&lt;/p&gt;
&lt;p&gt;- No super-user permissions remain in the system&lt;/p&gt;
&lt;p&gt;- Affects all users, organizations, and teams managed in the instance&lt;/p&gt;
&lt;p&gt;The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited when:&lt;/p&gt;
&lt;p&gt;1. An Organization administrator exists&lt;/p&gt;
&lt;p&gt;2. The Server administrator is either:&lt;/p&gt;
&lt;p&gt;- Not part of any organization, or
   - Part of the same organization as the Organization administrator
Impact:&lt;/p&gt;
&lt;p&gt;- Organization administrators can permanently delete Server administrator accounts&lt;/p&gt;
&lt;p&gt;- If the only Server administrator is deleted, the Grafana instance becomes unmanageable&lt;/p&gt;
&lt;p&gt;- No super-user permissions remain in the system&lt;/p&gt;
&lt;p&gt;- Affects all users, organizations, and teams managed in the instance&lt;/p&gt;
&lt;p&gt;The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-3580</guid>
    </item>
    <item>
      <title>GHSA-gcjf-8x3p-64v2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gcjf-8x3p-64v2</link>
      <description>&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited when:&lt;/p&gt;
&lt;p&gt;1. An Organization administrator exists&lt;/p&gt;
&lt;p&gt;2. The Server administrator is either:&lt;/p&gt;
&lt;p&gt;- Not part of any organization, or
   - Part of the same organization as the Organization administrator
Impact:&lt;/p&gt;
&lt;p&gt;- Organization administrators can permanently delete Server administrator accounts&lt;/p&gt;
&lt;p&gt;- If the only Server administrator is deleted, the Grafana instance becomes unmanageable&lt;/p&gt;
&lt;p&gt;- No super-user permissions remain in the system&lt;/p&gt;
&lt;p&gt;- Affects all users, organizations, and teams managed in the instance&lt;/p&gt;
&lt;p&gt;The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited when:&lt;/p&gt;
&lt;p&gt;1. An Organization administrator exists&lt;/p&gt;
&lt;p&gt;2. The Server administrator is either:&lt;/p&gt;
&lt;p&gt;- Not part of any organization, or
   - Part of the same organization as the Organization administrator
Impact:&lt;/p&gt;
&lt;p&gt;- Organization administrators can permanently delete Server administrator accounts&lt;/p&gt;
&lt;p&gt;- If the only Server administrator is deleted, the Grafana instance becomes unmanageable&lt;/p&gt;
&lt;p&gt;- No super-user permissions remain in the system&lt;/p&gt;
&lt;p&gt;- Affects all users, organizations, and teams managed in the instance&lt;/p&gt;
&lt;p&gt;The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gcjf-8x3p-64v2</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20654-1 — Security update for grafana</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20654-1</link>
      <description>&lt;p&gt;Security update for grafana&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grafana&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20654-1</guid>
    </item>
    <item>
      <title>SCA-2026-0002 — Vulnerabilities affecting SICK Incoming Goods Suite</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0002</link>
      <description>&lt;p&gt;An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01 A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources. The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript. A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01 A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources. The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript. A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0002</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01985-1 — Security update 4.3.15 for Multi-Linux Manager Server</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01985-1</link>
      <description>&lt;p&gt;Security update 4.3.15 for Multi-Linux Manager Server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update 4.3.15 for Multi-Linux Manager Server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01985-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-3580</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3580</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either:    - Not part of any organization, or    - Part of the same organization as the Organization administrator Impact: - Organization administrators can permanently delete Server administrator accounts - If the only Server administrator is deleted, the Grafana instance becomes unmanageable - No super-user permissions remain in the system - Affects all users, organizations, and teams managed in the instance The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either:    - Not part of any organization, or    - Part of the same organization as the Organization administrator Impact: - Organization administrators can permanently delete Server administrator accounts - If the only Server administrator is deleted, the Grafana instance becomes unmanageable - No super-user permissions remain in the system - Affects all users, organizations, and teams managed in the instance The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3580</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1133 — Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1133</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1133</guid>
    </item>
  </channel>
</rss>
