Grafana Improper Access Control Vulnerability - CVE-2026-28378
The public dashboard deletion endpoint does not enforce organization isolation allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard39s identifiers.