---
title: "Exposing a New BOLA Vulnerability in Grafana"
url: https://daily.dev/posts/exposing-a-new-bola-vulnerability-in-grafana-v86ffscbq
source_url: https://unit42.paloaltonetworks.com/new-bola-vulnerability-grafana/
type: article
source: "Unit 42"
published: 2024-03-27T14:11:31.376Z
updated: 2026-03-30T02:13:22.631Z
tags: ["data-observability", "grafana", "security", "vulnerability"]
reading_time: 9
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Exposing a New BOLA Vulnerability in Grafana

**[Unit 42](https://daily.dev/sources/unit42)** · 9 min read · 1 upvotes · 0 comments

## Summary

A new Broken Object Level Authorization (BOLA) vulnerability has been discovered in Grafana, impacting multiple versions. This vulnerability allows low-privileged users to delete dashboard snapshots belonging to other organizations. Attackers can potentially exploit these issues to access sensitive data or compromise data integrity. Mitigations and fixes have been released.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://unit42.paloaltonetworks.com/new-bola-vulnerability-grafana/>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#data-observability](https://daily.dev/tags/data-observability), [#grafana](https://daily.dev/tags/grafana), [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/exposing-a-new-bola-vulnerability-in-grafana-v86ffscbq)
