πŸ” CVE Alert

CVE-2026-9765

HIGH 7.1

CVE-2026-9765 CVE Record

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are β€œBroken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account

Vendor grafana
Product grafana irm
Ecosystems
Industries
Technology
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for grafana grafana irm

Be the first to know when new high vulnerabilities affecting grafana grafana irm are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Grafana / Grafana IRM
1.0.0 ≀ 1.164.0

References

NVD β†— CVE.org β†— EPSS Data β†—
grafana.com: https://grafana.com/security/security-advisories/cve-2026-9765