Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-21725

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.8%
CVSS Severity
CVSS v3 Score 2.6
Products affected by CVE-2026-21725
  • Grafana » Grafana » Version: 11.0.0
    cpe:2.3:a:grafana:grafana:11.0.0
  • Grafana » Grafana » Version: 11.0.5
    cpe:2.3:a:grafana:grafana:11.0.5
  • Grafana » Grafana » Version: 11.0.6
    cpe:2.3:a:grafana:grafana:11.0.6
  • Grafana » Grafana » Version: 11.1.6
    cpe:2.3:a:grafana:grafana:11.1.6
  • Grafana » Grafana » Version: 11.1.7
    cpe:2.3:a:grafana:grafana:11.1.7
  • Grafana » Grafana » Version: 11.2.1
    cpe:2.3:a:grafana:grafana:11.2.1
  • Grafana » Grafana » Version: 11.2.10
    cpe:2.3:a:grafana:grafana:11.2.10
  • Grafana » Grafana » Version: 11.2.2
    cpe:2.3:a:grafana:grafana:11.2.2
  • Grafana » Grafana » Version: 11.2.3
    cpe:2.3:a:grafana:grafana:11.2.3
  • Grafana » Grafana » Version: 11.2.8
    cpe:2.3:a:grafana:grafana:11.2.8
  • Grafana » Grafana » Version: 11.2.9
    cpe:2.3:a:grafana:grafana:11.2.9
  • Grafana » Grafana » Version: 11.3.0
    cpe:2.3:a:grafana:grafana:11.3.0
  • Grafana » Grafana » Version: 11.3.5
    cpe:2.3:a:grafana:grafana:11.3.5
  • Grafana » Grafana » Version: 11.3.6
    cpe:2.3:a:grafana:grafana:11.3.6
  • Grafana » Grafana » Version: 11.3.7
    cpe:2.3:a:grafana:grafana:11.3.7
  • Grafana » Grafana » Version: 11.3.8
    cpe:2.3:a:grafana:grafana:11.3.8
  • Grafana » Grafana » Version: 11.4.3
    cpe:2.3:a:grafana:grafana:11.4.3
  • Grafana » Grafana » Version: 11.4.4
    cpe:2.3:a:grafana:grafana:11.4.4
  • Grafana » Grafana » Version: 11.4.5
    cpe:2.3:a:grafana:grafana:11.4.5
  • Grafana » Grafana » Version: 11.4.6
    cpe:2.3:a:grafana:grafana:11.4.6
  • Grafana » Grafana » Version: 11.5.3
    cpe:2.3:a:grafana:grafana:11.5.3
  • Grafana » Grafana » Version: 11.5.4
    cpe:2.3:a:grafana:grafana:11.5.4
  • Grafana » Grafana » Version: 11.5.5
    cpe:2.3:a:grafana:grafana:11.5.5
  • Grafana » Grafana » Version: 11.5.6
    cpe:2.3:a:grafana:grafana:11.5.6
  • Grafana » Grafana » Version: 11.6.0
    cpe:2.3:a:grafana:grafana:11.6.0
  • Grafana » Grafana » Version: 11.6.1
    cpe:2.3:a:grafana:grafana:11.6.1
  • Grafana » Grafana » Version: 11.6.10
    cpe:2.3:a:grafana:grafana:11.6.10
  • Grafana » Grafana » Version: 11.6.2
    cpe:2.3:a:grafana:grafana:11.6.2
  • Grafana » Grafana » Version: 11.6.3
    cpe:2.3:a:grafana:grafana:11.6.3
  • Grafana » Grafana » Version: 11.6.9
    cpe:2.3:a:grafana:grafana:11.6.9
  • Grafana » Grafana » Version: 12.0.0
    cpe:2.3:a:grafana:grafana:12.0.0
  • Grafana » Grafana » Version: 12.0.1
    cpe:2.3:a:grafana:grafana:12.0.1
  • Grafana » Grafana » Version: 12.0.2
    cpe:2.3:a:grafana:grafana:12.0.2
  • Grafana » Grafana » Version: 12.0.6
    cpe:2.3:a:grafana:grafana:12.0.6
  • Grafana » Grafana » Version: 12.0.8
    cpe:2.3:a:grafana:grafana:12.0.8
  • Grafana » Grafana » Version: 12.1.3
    cpe:2.3:a:grafana:grafana:12.1.3
  • Grafana » Grafana » Version: 12.1.5
    cpe:2.3:a:grafana:grafana:12.1.5
  • Grafana » Grafana » Version: 12.2.1
    cpe:2.3:a:grafana:grafana:12.2.1
  • Grafana » Grafana » Version: 12.2.3
    cpe:2.3:a:grafana:grafana:12.2.3
  • Grafana » Grafana » Version: 12.2.4
    cpe:2.3:a:grafana:grafana:12.2.4
  • Grafana » Grafana » Version: 12.3.1
    cpe:2.3:a:grafana:grafana:12.3.1
  • Grafana » Grafana » Version: 12.3.2
    cpe:2.3:a:grafana:grafana:12.3.2


Contact Us

Shodan ® - All rights reserved