CVE-2026-9765

Grafana · Grafana IRM

A vulnerability in Grafana IRM allows authenticated users to perform unauthorized actions, potentially impacting system integrity and availability.

Executive summary

Grafana IRM versions 1.0.0 through 1.164.0 are affected by a high-severity vulnerability that permits authenticated users to compromise system integrity.

Vulnerability

This vulnerability involves an improper authorization flaw, which allows an authenticated attacker with low privileges to perform unauthorized modifications or disrupt service availability within the platform.

Business impact

The exploitation of this vulnerability could lead to significant unauthorized changes to incident response configurations or service disruptions, directly impacting operational continuity. With a CVSS score of 7.1, the risk is categorized as High because it allows an attacker to manipulate core system functions despite requiring authenticated access. Failure to address this flaw may result in the corruption of critical incident data or unauthorized access to sensitive workflow parameters.

Remediation

Immediate Action: Update Grafana IRM to the latest vendor-supplied patch version as detailed in the official security advisory.

Proactive Monitoring: Review audit logs for suspicious activity involving user-initiated configuration changes or unexpected spikes in service resource consumption.

Compensating Controls: Implement strict access control lists and principle of least privilege policies to limit the potential impact of an authenticated user session being compromised.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for unauthorized system modifications, administrators should prioritize applying the security updates provided by Grafana. Ensure that all users maintain strong, unique credentials to mitigate the risk of account compromise, which is a prerequisite for exploiting this vulnerability.