{"schema_version":"1.9.0","id":"BIT-grafana-2026-21725","published":"2026-03-02T08:41:16.926Z","modified":"2026-09-08T08:47:51.128437952Z","aliases":["CVE-2026-21725"],"summary":"Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name","details":"A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so.\n\nThis requires several very stringent conditions to be met:\n\n- The attacker must have admin access to the specific datasource prior to its first deletion.\n- Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana.\n- The attacker must delete the datasource, then someone must recreate it.\n- The new datasource must not have the attacker as an admin.\n- The new datasource must have the same UID as the prior datasource. These are randomised by default.\n- The datasource can now be re-deleted by the attacker.\n- Once 30 seconds are up, the attack is spent and cannot be repeated.\n- No datasource with any other UID can be attacked.","affected":[{"package":{"name":"grafana","ecosystem":"Bitnami","purl":"pkg:bitnami/grafana"},"ranges":[{"type":"SEMVER","events":[{"introduced":"11.0.0"},{"fixed":"12.4.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-21725.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N"}]}],"references":[{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2026-21725"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21725"}],"database_specific":{"cpes":["cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*"],"severity":"Low"}}