Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-36062

18
FAUCET Score

CVE-2022-36062 is a low-severity privilege escalation vulnerability affecting Grafana versions prior to 8.5.13, 9.0.9, and 9.1.6. It occurs when Role-Based Access Control (RBAC) is enabled after being disabled, leading to improper permission preservation on folders where only Admin permissions were initially set. This allows Editors and Viewers to gain unauthorized access to edit and view these folders. The CVSS score is 3.8 (Low), indicating a network attack vector with low complexity, requiring high privileges, and resulting in limited confidentiality and integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 8.5.13CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.9CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 9.1.0, < 9.1.6CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.64%
Probability of exploitation in next 30 days
EPSS Percentile
46.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 68th percentile among its peer group of 709 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 8.5.13
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 9.0.9
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 9.1.6
nodejspatch availablevia llm_extracted
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

goGHSA-p978-56hq-r492high

Grafana folders admin only permission privilege escalation

May 14, 2024
redhatCVE-2022-36062Moderate

grafana: Grafana RBAC folders/dashboards privilege escalation

Sep 20, 2022
zimbrallm-zimbra-7ed326713453eee7HIGH

Privilege Escalation in Folder Permissions in Grafana

Sep 20, 2022
kenticollm-kentico-c25a8eae63eff569HIGH

Privilege Escalation in Folder Permissions in Grafana

Sep 20, 2022
chainsafellm-chainsafe-156807a79580f4e7HIGH

Privilege Escalation in Folder Permissions in Grafana

Sep 20, 2022
apollographqlllm-apollographql-dbf570700656b4b5HIGH

Privilege Escalation in Folder Permissions in Grafana

Sep 20, 2022
jenkinsllm-jenkins-211c44ab715a436aHIGH

Privilege Escalation in Folder Permissions in Grafana

Sep 20, 2022
nodejsllm-nodejs-c32963861fe59a0cHIGH

Privilege Escalation in Folder Permissions in Grafana

Sep 20, 2022

References

github.com / grafana/grafana/security/advisories/GHSA-p978-56hq-r492
PatchRelease NotesVendor Advisory
security.netapp.com / advisory/ntap-20221215-0001
Third Party Advisory