{"schema_version":"1.9.0","id":"CVE-2026-21725","published":"2026-02-25T12:35:43.104Z","modified":"2026-08-28T11:30:27.296757748Z","aliases":["BIT-grafana-2026-21725"],"related":["CGA-wc22-f84p-j8f7","SUSE-SU-2026:1524-1","SUSE-SU-2026:2243-1","SUSE-SU-2026:2258-1","SUSE-SU-2026:3718-1","openSUSE-SU-2026:10601-1","openSUSE-SU-2026:20940-1","openSUSE-SU-2026:21351-1"],"summary":"Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name","details":"A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so.\n\nThis requires several very stringent conditions to be met:\n\n- The attacker must have admin access to the specific datasource prior to its first deletion.\n- Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana.\n- The attacker must delete the datasource, then someone must recreate it.\n- The new datasource must not have the attacker as an admin.\n- The new datasource must have the same UID as the prior datasource. These are randomised by default.\n- The datasource can now be re-deleted by the attacker.\n- Once 30 seconds are up, the attack is spent and cannot be repeated.\n- No datasource with any other UID can be attacked.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grafana/grafana","events":[{"introduced":"277ef258d4b9a5acdf2932347c6a4ca72d739b28"},{"fixed":"46a02dc12a085445ab105b72fa159248f7d1dc9d"}],"database_specific":{"cpe":"cpe:2.3:a:grafana:grafana:*:-:*:*:enterprise:*:*:*","extracted_events":[{"introduced":"11.0.0"},{"fixed":"12.4.1"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21725.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21725.json"},{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2026-21725"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21725"}],"database_specific":{"cna_assigner":"GRAFANA","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21725.json","unresolved_ranges":[{"extracted_events":[{"introduced":"v11.0.0"},{"fixed":"v12.4.1"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"}]}