Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-72585-PoC — PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5) | Kitploit
Tools/GitHubGitHub/nel-droid/cve-2026-72585-poc
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationAPI Security
GitHubnel-droid/cve-2026-72585-poc

CVE-2026-72585-PoC

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

View Repository
121 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-72585 — Grafana: Incomplete Fix for CVE-2026-21724 Allows Editor Role to Delete Protected Contact Points

Product: Grafana (Grafana Labs) — through 13.2.0 File: pkg/services/ngalert/provisioning/contactpoints.go CWE: CWE-284 — Improper Access Control CVSS 3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N — 6.5 (Medium) CNA: Turan Security · CVE record Related: CVE-2026-21724 (the original fix this bypasses)

Description

An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (alert notification receivers) without holding the required alert.notifications.receivers.protected:write permission. This is an incomplete fix for the prior advisory CVE-2026-21724, which introduced the "protected contact point" concept but missed enforcing the permission check on the delete path.

Impact

An Editor — a role explicitly intended to have less privilege than Admin over protected alerting configuration — can delete contact points marked as protected, silencing or redirecting critical alert notifications (e.g. PagerDuty/Slack/email escalation paths) without the elevated permission the platform is supposed to require for that action.

Reproduction

  1. Authenticate as a user holding only the Editor organization role (not Admin, and without alert.notifications.receivers.protected:write).
  2. Identify a contact point marked provisioned/protected via the provisioning API:
    GET /api/v1/provisioning/contact-points
    Authorization: Bearer <editor token>
    
  3. Send a delete request for that protected contact point's UID:
    DELETE /api/v1/provisioning/contact-points/<uid>
    Authorization: Bearer <editor token>
    
  4. The deletion succeeds despite the Editor lacking alert.notifications.receivers.protected:write — the delete handler in contactpoints.go does not re-check the protected-write permission that CVE-2026-21724 added for other mutation paths.

Root Cause

The permission check added to close CVE-2026-21724 was applied inconsistently across the contact-point provisioning handlers — the delete path was missed.

Fix Recommendation

Apply the same alert.notifications.receivers.protected:write permission check to the delete handler that was applied to create/update handlers when closing CVE-2026-21724.

Download Tool