CVE-2026-9765
Grafana · Grafana IRM
A vulnerability in Grafana IRM allows authenticated users to perform unauthorized actions, potentially impacting system integrity and availability.
Executive summary
Grafana IRM versions 1.0.0 through 1.164.0 are affected by a high-severity vulnerability that permits authenticated users to compromise system integrity.
Vulnerability
This vulnerability involves an improper authorization flaw, which allows an authenticated attacker with low privileges to perform unauthorized modifications or disrupt service availability within the platform.
Business impact
The exploitation of this vulnerability could lead to significant unauthorized changes to incident response configurations or service disruptions, directly impacting operational continuity. With a CVSS score of 7.1, the risk is categorized as High because it allows an attacker to manipulate core system functions despite requiring authenticated access. Failure to address this flaw may result in the corruption of critical incident data or unauthorized access to sensitive workflow parameters.
Remediation
Immediate Action: Update Grafana IRM to the latest vendor-supplied patch version as detailed in the official security advisory.
Proactive Monitoring: Review audit logs for suspicious activity involving user-initiated configuration changes or unexpected spikes in service resource consumption.
Compensating Controls: Implement strict access control lists and principle of least privilege policies to limit the potential impact of an authenticated user session being compromised.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for unauthorized system modifications, administrators should prioritize applying the security updates provided by Grafana. Ensure that all users maintain strong, unique credentials to mitigate the risk of account compromise, which is a prerequisite for exploiting this vulnerability.