A user changing their email after signing up and verifying it can change it without verification in profile settings.
The configuration option "verifyemailenabled" will only validate email only on sign up.
{
"cpes": [
"cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:grafana:grafana:*:*:*:*:*:go:*:*"
],
"severity": "Medium"
}