Grafana folders admin only permission privilege escalation
Published Sep 22, 2022
7.2
HIGHCVSS 4.0
EPSS 0.75%
Description
Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating legacy folder permissions to RBAC permissions do not account for the scenario where the only user permission in the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them to edit and view folders accordingly. This issue has been patched in versions 8.5.13, 9.0.9, and 9.1.6. A workaround when the impacted folder/dashboard is known is to remove the additional permissions manually.
Affected products
-
- Version < 8.5.13StatusaffectedConstraints-
- Version >= 9.1.0, < 9.1.6StatusaffectedConstraints-
- Version >= 9.0.0, < 9.0.9StatusaffectedConstraints-
- Version
No data.
OpenShift Service Mesh 2.0
servicemesh-grafana
Not affected
OpenShift Service Mesh 2.1
servicemesh-grafana
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Not affected
Red Hat Ceph Storage 3
grafana
Not affected
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Not affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat Storage 3
grafana
Not affected
Red Hat build of Quarkus
grafana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Not affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 3 | grafana | Not affected | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat Storage 3 | grafana | Not affected | n/a |
| Red Hat build of Quarkus | grafana | Not affected | n/a |
github.com/grafana/grafana
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/grafana/grafana | 0 | not fixed |
Remediation
Red Hat statement
Grafana RBAC is available in Grafana Enterprise, which is not shipped in any of the Red Hat products.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
2 other sources (GHSA, Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.75% (0.00749) | 53.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.60% (0.00596) | 43.62th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00057) | 14.92th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00054) | 24.72th | v3 (v2023.03.01) |
| Jul 17, 2024 | 0.05% (0.00054) | 23.20th | v3 (v2023.03.01) |
| Apr 14, 2024 | 0.05% (0.00054) | 21.19th | v3 (v2023.03.01) |
| Sep 29, 2023 | 0.05% (0.00053) | 18.96th | v3 (v2023.03.01) |
| Aug 23, 2023 | 0.05% (0.00048) | 14.96th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00045) | 11.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 23, 2022 | 0.89% (0.00885) | 26.38th | v2 (v2022.01.01) |
References (7)
- https://access.redhat.com/security/cve/CVE-2022-36062 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2125521 Issue Tracking
- https://github.com/advisories/GHSA-p978-56hq-r492 Advisory
- https://github.com/grafana/grafana/security/advisories/GHSA-p978-56hq-r492 PatchRelease NotesVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36062
- https://security.netapp.com/advisory/ntap-20221215-0001 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-36062
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-36062 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2125521 | Issue Tracking | |
| https://github.com/advisories/GHSA-p978-56hq-r492 | Advisory | |
| https://github.com/grafana/grafana/security/advisories/GHSA-p978-56hq-r492 | PatchRelease NotesVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-36062 | ||
| https://security.netapp.com/advisory/ntap-20221215-0001 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-36062 |
Change history (3)
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC technical impact changed from total to
partial
- CISA ADP
- SSVC technical impact changed from partial to
total partial → total
- SSVC technical impact changed from partial to
total
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC technical impact changed from total to
partial