CVE-2021-27358
HIGH EXPLOITED NUCLEIGrafana 6.7.3-7.4.1 - Unauthenticated Denial of Service via Snapshot API
Title source: llmExploitation Summary
CVE-2021-27358 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
Nuclei Templates (1)
Grafana Unauthenticated Snapshot Creation
HIGHby pdteam,bing0o
Shodan:
title:"Grafana" || cpe:"cpe:2.3:a:grafana:grafana" || http.title:"grafana"
FOFA:
title="grafana" || app="grafana"
References (4)
Core 4
Core References
Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/grafana/grafana/blob/master/CHANGELOG.md
Release Notes, Vendor Advisory x_refsource_confirm
https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/
Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/grafana/grafana/blob/master/CHANGELOG.md#742-2021-02-17
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210513-0007/
Scores
CVSS v3
7.5
EPSS
0.8304
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
VulnCheck KEV
2026-05-01
Status
published
Products (3)
grafana/grafana
6.7.3 - 7.4.1
grafana/grafana
6.7.3 - 7.4.2Go
netapp/e-series_performance_analyzer
Published
Mar 18, 2021
Tracked Since
Feb 18, 2026