THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-21727 (LOW 3.3) — A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could r

[NVD] CVE-2026-21727 (LOW 3.3) — A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could r

lownvdPublished 2026-04-15

CVE-2026-21727 CVSS: 3.3 LOW Published: 2026-04-15T20:16:34.290

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belo

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21727