THREAT OPS › Threat News › [NVD] CVE-2026-21727 (LOW 3.3) — A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could r
[NVD] CVE-2026-21727 (LOW 3.3) — A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could r
CVE-2026-21727 CVSS: 3.3 LOW Published: 2026-04-15T20:16:34.290
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belo
Indicators of compromise
- CVE-2026-21727cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21727