Time-of-check Time-of-use (TOCTOU) Affecting grafana-12.4 package, versions <12.4.1-r0


Severity

Recommended
0.0
low
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Time-of-check Time-of-use (TOCTOU) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-MINIMOSLATEST-GRAFANA124-15441233
  • published10 Mar 2026
  • disclosed25 Feb 2026

Introduced: 25 Feb 2026

CVE-2026-21725  (opens in a new tab)
CWE-367  (opens in a new tab)

How to fix?

Upgrade Minimos:latest grafana-12.4 to version 12.4.1-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream grafana-12.4 package and not the grafana-12.4 package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so.

This requires several very stringent conditions to be met:

  • The attacker must have admin access to the specific datasource prior to its first deletion.
  • Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana.
  • The attacker must delete the datasource, then someone must recreate it.
  • The new datasource must not have the attacker as an admin.
  • The new datasource must have the same UID as the prior datasource. These are randomised by default.
  • The datasource can now be re-deleted by the attacker.
  • Once 30 seconds are up, the attack is spent and cannot be repeated.
  • No datasource with any other UID can be attacked.

CVSS Base Scores

version 3.1