Authorization Bypass Through User-Controlled Key Affecting grafana13.2 package, versions <0:13.2.1-0.1.hum1


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.4% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-GRAFANA132-19647509
  • published9 Sept 2026
  • disclosed24 Jul 2026

Introduced: 24 Jul 2026

CVE-2026-9765  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade RHEL:10 grafana13.2 to version 0:13.2.1-0.1.hum1 or higher.
This issue was patched in RHSA-2026:63164.

NVD Description

Note: Versions mentioned in the description apply only to the upstream grafana13.2 package and not the grafana13.2 package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue.

Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions.

Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account

CVSS Base Scores

version 3.1