HIGHGo →
Grafana: Users can generate Service Account tokens after permissions removal
Grafana: Users can generate Service Account tokens after permissions removal
Affected packages
- github.com/grafana/grafana
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-33381
- https://github.com/grafana/grafana/commit/fb7336fc36c14e1ff869482c5085ddb9f39e1b86
- https://github.com/grafana/grafana
- https://grafana.com/security/security-advisories/cve-2026-33381
Structured record: https://osv.dev/vulnerability/GHSA-wfhv-mj62-f5xh
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta