grafana vendor intelligence

grafana Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting grafana products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
6
Known exploited vulnerabilities affecting grafana products
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
grafana KEVs with sensor-observed exploitation activity

The catalog gap matters for grafana exposure

Four of the six exploited grafana CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss two-thirds of this vendor portfolio.

33%
Covered by CISA
67%
Beyond CISA
2
Product families

Attested grafana CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2021-27358

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API...

Grafana High Beyond CISA 07 Jun 2026
CVE-2020-13379

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated...

Grafana High Beyond CISA 04 Jun 2026
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers...

Grafana High Beyond CISA 17 Jun 2025
CVE-2021-43798

Grafana path traversal

grafana Confirmed In CISA 01 Jun 2026
CVE-2025-3415

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could...

Grafana High Beyond CISA 17 Jul 2025
CVE-2021-39226

Snapshot authentication bypass in grafana

grafana Confirmed In CISA 25 Aug 2022

Showing 6 of 6 grafana known exploited vulnerabilities.

Recurring weakness patterns

Exposure, limitation, and authentication account for three mapped occurrences across this grafana KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.