CVE-2021-39226Grafana Authentication Bypass Vulnerability

PUBLISHEDvulnerability record
2022-08-25 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2021-39226
Project:
Grafana Labs
Product:
Grafana
Date Added:
2022-08-25
Due Date:
2022-09-15
Last Updated:
June 21, 2025

Vulnerability Name

Grafana Authentication Bypass Vulnerability

Description

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
Unknown

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses