ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Grafana flaw to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2021-43798

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-43798
Unauthenticated Path Traversal File Read in Grafana 8.x

CVE-2021-43798 is a path traversal flaw (CWE-22) in Grafana's plugin-serving endpoint that allows unauthenticated remote attackers to read arbitrary files from the server's local filesystem. It is triggered by crafted HTTP requests to the /public/plugins/<plugin-id>/ path, where the traversal payload can use any installed plugin's ID, and no authentication or user interaction is required. An attacker gains read access to local files on the Grafana host, which can expose configuration files, credentials, and other sensitive data (confidentiality impact only; no integrity or availability impact). Self-managed Grafana installations running versions 8.0.0-beta1 through 8.3.0 (other than the patched releases) are affected; Grafana Cloud was never vulnerable. Exploitation is well established: a public proof-of-concept exists, exploitation probability is very high (EPSS 88.5%, 100th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-09.

Do: Upgrade self-managed Grafana to 8.0.7, 8.1.8, 8.2.7, or 8.3.1 (or any later patched release); Grafana Cloud customers need take no action. Until patched, restrict or monitor access to /public/plugins/ and inspect web server, proxy, and Grafana access logs for traversal sequences against any installed plugin ID to detect file-read attempts. As a CISA KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if patching is not possible.

7.589% KEV PoC
  • Grafana Labs Grafana (self-managed/open-source; Grafana Cloud not affected) 8.0.0-beta1 through 8.3.0, excluding patched releases 8.0.7, 8.1.8, 8.2.7, and 8.3.1
mass≈100,000+ internet-exposed Grafana instances (public internet scan data); total installed base unknown
Full article212 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Grafana flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Grafana flaw, tracked as CVE-2021-43798 (CVSS score 7.5), to its Known Exploited Vulnerabilities (KEV) catalog.

Grafana is an open-source platform for monitoring and observability. 

This flaw is a directory traversal vulnerability affecting versions 8.0.0-beta1 through 8.3.0 (except patched releases). Attackers can exploit the flaw to access local files on the server by manipulating the plugin path in the URL:

<grafana_host_url>/public/plugins/<plugin-id>/

By exploiting this path, an attacker could read sensitive files outside the intended directories, potentially exposing system or configuration data.

Grafana Cloud was never affected, but self-hosted instances must update to versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1 to fix the issue.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by October 30, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/183192/hacking/u-s-cisa-adds-grafana-flaw-to-its-known-exploited-vulnerabilities-catalog.html