A user changing their email after signing up and verifying it can change it without verification in profile settings.The configuration option "verifyemailenabled" will only validate email only on sign up.
{ "cpes": [ "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*", "cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*", "cpe:2.3:a:grafana:grafana:*:*:*:*:*:go:*:*" ], "severity": "Medium" }