CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
More information : https://grafana.com/security/security-advisories/cve-2026-33377
