Database/Control plane, storage & DevOps
Grafana: Unauthenticated access to snapshots via /api/snapshots/:key
CVSS 9.8CVE-2021-39226Control plane, storage & DevOpsKnown exploitedcurated
Impact
Unauthenticated access to snapshots via /api/snapshots/:key -> view and delete snapshot data
Who can reach it
Network (remote)
What to do
Control-plane: upgrade the monitoring tier
References
Related entries
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCVE-2023-3128 · GrafanaCritical
- Grafana: Client path traversal + open redirectCVE-2025-4123 · GrafanaHigh
- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/CVE-2021-43798 · GrafanaHigh
- Grafana: Stored XSS via Unified AlertingCVE-2022-31097 · GrafanaHigh
- Grafana: A user can block another user's login by registering their email address as a usernameCVE-2022-39229 · GrafanaMedium
- Grafana: SQL Expressions passes user input to duckdb unsanitizedCVE-2024-9264 · GrafanaCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.