CISA Known Exploited Vulnerability

CVE-2021-39226

Grafana Labs · Grafana

Grafana Authentication Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-287
Ransomware Unknown

CISA description

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

Required action

Apply updates per vendor instructions.