CVE-2026-21724 | Grafana OSS up to 11.6.13/12.1.9/12.2.7/12.3.5 Provisioning Contact Points API authorization
A vulnerability, which was classified as critical, was found in Grafana OSS up to 11.6.13/12.1.9/12.2.7/12.3.5. Affected is an unknown function of the component Provisioning Contact Points API. Such manipulation leads to authorization bypass.
This vulnerability is documented as CVE-2026-21724. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.