AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-21727.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSLOW / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

--- hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana fixed_versions: - ">=11.6.11 >=12.0.9 >=12.1.6 >=12.2.4" --- A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization. This issue affects correlations created prior to Grafana 10.2 and is fixed in >=11.6.11, >=12.0.9, >=12.1.6, and >=12.2.4. Thanks to Gyu-hyeok Lee (g2h) for reporting this vulnerability.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-p5x9-j974-rpfp

Open original source · Updated Oct 05, 2026

Grafana legacy correlations allow cross-tenant disclosure and deletion

Source severity: LOW / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/grafana/grafana< 1.9.2-0.20260127141016-e702db6096e01.9.2-0.20260127141016-e702db6096e0

Original records & references

PUBLISHED 2026-04-15T17:30:18-04:00
MODIFIED 2026-10-05T18:33:26-04:00
INGESTED 2026-10-06T11:45:33-04:00