EXPOSURES › CVE-2021-39226
CVE-2021-39226
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⌖ EXPLOITED IN THE WILD
SHAME 90/100
exploited-in-wildunpatchedauth-bypass
Grafana suffered an unpatched authentication bypass allowing unauthenticated users to delete snapshots, potentially leading to data loss.
Grafana Labs' Grafana product had an unpatched authentication bypass vulnerability that enabled unauthenticated users to delete snapshots, posing a risk of complete data loss.
Shame score — Unpatched vulnerability enabling unauthenticated deletion of critical data.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.