
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
Product: Grafana (Grafana Labs) — through 13.2.0
File: pkg/services/ngalert/provisioning/contactpoints.go
CWE: CWE-284 — Improper Access Control
CVSS 3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N — 6.5 (Medium)
CNA: Turan Security · CVE record
Related: CVE-2026-21724 (the original fix this bypasses)
An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to
delete protected contact points (alert notification receivers) without holding the required
alert.notifications.receivers.protected:write permission. This is an incomplete fix for the
prior advisory CVE-2026-21724, which introduced the "protected contact point" concept but
missed enforcing the permission check on the delete path.
An Editor — a role explicitly intended to have less privilege than Admin over protected alerting configuration — can delete contact points marked as protected, silencing or redirecting critical alert notifications (e.g. PagerDuty/Slack/email escalation paths) without the elevated permission the platform is supposed to require for that action.
Editor organization role (not Admin, and without
alert.notifications.receivers.protected:write).provisioned/protected via the provisioning API:
GET /api/v1/provisioning/contact-points
Authorization: Bearer <editor token>
DELETE /api/v1/provisioning/contact-points/<uid>
Authorization: Bearer <editor token>
alert.notifications.receivers.protected:write
— the delete handler in contactpoints.go does not re-check the protected-write permission
that CVE-2026-21724 added for other mutation paths.The permission check added to close CVE-2026-21724 was applied inconsistently across the contact-point provisioning handlers — the delete path was missed.
Apply the same alert.notifications.receivers.protected:write permission check to the delete
handler that was applied to create/update handlers when closing CVE-2026-21724.