CVE-2021-43798
KEV PoC massUnauthenticated Path Traversal File Read in Grafana 8.x
CISA: Grafana Path Traversal Vulnerability
CVE-2021-43798 is a path traversal flaw (CWE-22) in Grafana's plugin-serving endpoint that allows unauthenticated remote attackers to read arbitrary files from the server's local filesystem. It is triggered by crafted HTTP requests to the /public/plugins/<plugin-id>/ path, where the traversal payload can use any installed plugin's ID, and no authentication or user interaction is required. An attacker gains read access to local files on the Grafana host, which can expose configuration files, credentials, and other sensitive data (confidentiality impact only; no integrity or availability impact). Self-managed Grafana installations running versions 8.0.0-beta1 through 8.3.0 (other than the patched releases) are affected; Grafana Cloud was never vulnerable. Exploitation is well established: a public proof-of-concept exists, exploitation probability is very high (EPSS 88.5%, 100th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-09.
What to do: Upgrade self-managed Grafana to 8.0.7, 8.1.8, 8.2.7, or 8.3.1 (or any later patched release); Grafana Cloud customers need take no action. Until patched, restrict or monitor access to /public/plugins/ and inspect web server, proxy, and Grafana access logs for traversal sequences against any installed plugin ID to detect file-read attempts. As a CISA KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if patching is not possible.
| Grafana Labs Grafana (self-managed/open-source; Grafana Cloud not affected) | 8.0.0-beta1 through 8.3.0, excluding patched releases 8.0.7, 8.1.8, 8.2.7, and 8.3.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: ` /public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.
- Affected
- Grafana Labs Grafana
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- grafana
- Products
- grafana
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N