LOW

CVE-2026-21725

CVSS v3

2.6

LOW

EPSS Score

0.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The n

Technical details

CVSS v3 Vector
3.1
Published
2/25/2026
Last Modified
2/27/2026

Frequently asked questions

What is CVE-2026-21725?

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The n

Is CVE-2026-21725 actively exploited?

Active exploitation of CVE-2026-21725 has not been confirmed. The EPSS score is 0.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-21725?

CVE-2026-21725 has a CVSS v3 base score of 2.6 (LOW severity), with vector string 3.1.

Is CVE-2026-21725 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.