CVE Feed

    Dashboard / CVE / CVE-2023-4822

    CVE-2023-4822

    Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations. It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally. This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user. The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.

    Published:Oct 12, 2023
    Last Modified:Jan 30, 2026
    EPS:Oct 16, 2023
    EPSS Score:0.00453
    CVSS Score:6.7

    Affected Products

    Vendor
    Grafana
    Product
    Grafana
    Vendor
    Grafana
    Product
    Grafana Enterprise
    Vendor
    Redhat
    Product
    Ceph Storage

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High