CVE-2026-21720 | Grafana up to 11.6.8/12.0.7/12.1.4/12.2.2/12.3.0 Gravatar Image /avatar/:hash random values (WID-SEC-2026-0224)
A vulnerability labeled as problematic has been found in Grafana up to 11.6.8/12.0.7/12.1.4/12.2.2/12.3.0. Affected is an unknown function of the file /avatar/:hash of the component Gravatar Image Handler. Such manipulation leads to insufficiently random values.
This vulnerability is listed as CVE-2026-21720. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.