ZeroHour
The Recordpublished ()ingested

Grafana releases security patch after exploit for severe bug goes public

criticalVulnerability exploited in the wildimportance 60CVE-2021-43798

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-43798
Unauthenticated Path Traversal File Read in Grafana 8.x

CVE-2021-43798 is a path traversal flaw (CWE-22) in Grafana's plugin-serving endpoint that allows unauthenticated remote attackers to read arbitrary files from the server's local filesystem. It is triggered by crafted HTTP requests to the /public/plugins/<plugin-id>/ path, where the traversal payload can use any installed plugin's ID, and no authentication or user interaction is required. An attacker gains read access to local files on the Grafana host, which can expose configuration files, credentials, and other sensitive data (confidentiality impact only; no integrity or availability impact). Self-managed Grafana installations running versions 8.0.0-beta1 through 8.3.0 (other than the patched releases) are affected; Grafana Cloud was never vulnerable. Exploitation is well established: a public proof-of-concept exists, exploitation probability is very high (EPSS 88.5%, 100th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-09.

Do: Upgrade self-managed Grafana to 8.0.7, 8.1.8, 8.2.7, or 8.3.1 (or any later patched release); Grafana Cloud customers need take no action. Until patched, restrict or monitor access to /public/plugins/ and inspect web server, proxy, and Grafana access logs for traversal sequences against any installed plugin ID to detect file-read attempts. As a CISA KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if patching is not possible.

7.589% KEV PoC
  • Grafana Labs Grafana (self-managed/open-source; Grafana Cloud not affected) 8.0.0-beta1 through 8.3.0, excluding patched releases 8.0.7, 8.1.8, 8.2.7, and 8.3.1
mass≈100,000+ internet-exposed Grafana instances (public internet scan data); total installed base unknown
Full article363 words · extracted from therecord.media · click to collapse

Grafana Labs has released an emergency security update today to patch a critical vulnerability after security researchers released proof-of-concept code to exploit the issue over the weekend.

The vulnerability, tracked as CVE-2021-43798, impacts the company's main product, the Grafana dashboard, used by companies across the globe to monitor and aggregate logs and other parameters from across their local or remote networks.

Described as a path traversal attack, the vulnerability can allow an attacker to read files outside the Grafana application's folder.

For example, an attacker can abuse Grafana plugin URLs to escape the Grafana app folder and gain access to files stored on the underlying server, such as files storing passwords and configuration settings—details that the attacker could weaponize in subsequent attacks.

All Grafana self-hosted servers running 8.x versions of the software are considered vulnerable.

The issue was patched today with the release of Grafana 8.3.1, 8.2.7, 8.1.8, and 8.0.7. In its patch notes, Grafana Labs said that its cloud-hosted Grafana dashboards were not impacted by this vulnerability, which benefited from additional security protections.

Earlier today, The Record learned of such code being shared on Twitter and GitHub. We reached out to the company, which released a security update a few hours later.

Grafana did say in its statement that it was aware of the issue since last week, when it initially received a bug report, but was eventually forced into releasing an emergency patch earlier today after proof-of-concept code to exploit the bug was published online.

Several security researchers also claimed online today that the issue was being actively exploited in real-world attacks, but it was unclear if the exploitation was being done by bug bounty hunters or by malicious entities.

The Record could not confirm the nature of these exploitation attempts with independent third parties. There are currently between 3,000 and 5,000 Grafana servers exposed online, almost all exclusively used to monitor large corporate networks.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/grafana-releases-security-patch-after-exploit-for-severe-bug-goes-public