Skip to content
COOEY

EXPOSURES › CVE-2021-39226

CVE-2021-39226

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-39226 ↗
⌖ EXPLOITED IN THE WILD SHAME 90/100 exploited-in-wildunpatchedauth-bypass

Grafana suffered an unpatched authentication bypass allowing unauthenticated users to delete snapshots, potentially leading to data loss.

Grafana Labs' Grafana product had an unpatched authentication bypass vulnerability that enabled unauthenticated users to delete snapshots, posing a risk of complete data loss.

Shame score — Unpatched vulnerability enabling unauthenticated deletion of critical data.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.