Grafana Annotation Deletion Vulnerability for Editors

Vulnerability

A vulnerability exists in Grafana that allows editors to delete any annotation, regardless of their access rights. This issue arises because editors can remove annotations they cannot create or read.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of annotations, potentially disrupting collaboration and data tracking.

Added: May 13, 2026, 8:31 PM
Updated: May 13, 2026, 8:31 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.6
exploitability
5.2
remediation
0.0
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.