Improper authorization control for web services In grafana

Description

A flaw was found in Grafana. An improper access control issue at the /api/org/users/ API endpoint allows an Organization administrator to permanently delete a Server administrator account, leading to a complete loss of administrative control.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package