CVE detail
CVE-2026-21721
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:41064access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/errata/RHSA-2026:40138access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21721.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJan 27, 2026, 9:15 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2433242bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/security/cve/CVE-2026-21721access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/errata/RHSA-2026:8229access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/errata/RHSA-2026:5633access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/errata/RHSA-2026:3529access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/errata/RHSA-2026:3078access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/errata/RHSA-2026:2920access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM - https://access.redhat.com/errata/RHSA-2026:2914access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 27, 2026, 9:15 AM No excerpt available.
Vendor Advisorygrafana.comJan 27, 2026, 9:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-21713CVSS 4.3 · Medium
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/…
- CVE-2026-47407CVSS 9.4 · Critical
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{works…
- CVE-2026-55518CVSS 9.6 · Critical
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and G…
- CVE-2026-43977CVSS 7.5 · High
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history,…
- CVE-2026-35210CVSS 7.1 · High
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vulnerability in OpenCTI allows a…
- CVE-2026-28740CVSS 7.1 · High
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.