<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 01:48:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02572</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02572</link>
      <description>bdu:2024-02572</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02572</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0847 — Une vulnérabilité a été découverte dans Grafana. Elle permet à un
attaquant de provoquer une élévation de privilèges.</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0847</link>
      <description>certfr-2023-avi-0847</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0847</guid>
    </item>
    <item>
      <title>EUVD-2026-266988</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266988</link>
      <description>EUVD-2026-266988</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266988</guid>
    </item>
    <item>
      <title>fkie_cve-2023-4822</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-4822</link>
      <description>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.&lt;/p&gt;
&lt;p&gt;It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally.&lt;/p&gt;
&lt;p&gt;This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user.&lt;/p&gt;
&lt;p&gt;The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.&lt;/p&gt;
&lt;p&gt;It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally.&lt;/p&gt;
&lt;p&gt;This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user.&lt;/p&gt;
&lt;p&gt;The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-4822</guid>
    </item>
    <item>
      <title>GHSA-fw9c-75hh-89p6 — Grafana privilege escalation vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fw9c-75hh-89p6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. The vulnerability impacts instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.&lt;/p&gt;
&lt;p&gt;It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally.&lt;/p&gt;
&lt;p&gt;This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user.&lt;/p&gt;
&lt;p&gt;The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. The vulnerability impacts instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.&lt;/p&gt;
&lt;p&gt;It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally.&lt;/p&gt;
&lt;p&gt;This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user.&lt;/p&gt;
&lt;p&gt;The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fw9c-75hh-89p6</guid>
    </item>
    <item>
      <title>gsd-2023-4822</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-4822</link>
      <description>gsd-2023-4822</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-4822</guid>
    </item>
    <item>
      <title>RHSA-2024:3925 — Red Hat Security Advisory: Red Hat Ceph Storage 7.1 security, enhancements, and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3925</link>
      <description>&lt;p&gt;grafana: account takeover possible when using Azure AD OAuth grafana: incorrect assessment of permissions across organizations go-git: Maliciously crafted Git server replies can cause DoS on go-git clients go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana: account takeover possible when using Azure AD OAuth grafana: incorrect assessment of permissions across organizations go-git: Maliciously crafted Git server replies can cause DoS on go-git clients go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3925</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-4822</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4822</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations. It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally. This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user. The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations. It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally. This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user. The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4822</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2646 — Grafana: Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2646</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2646</guid>
    </item>
  </channel>
</rss>
