CVE-2021-27358

HIGH EXPLOITED NUCLEI

Grafana 6.7.3-7.4.1 - Unauthenticated Denial of Service via Snapshot API

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-27358 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

Nuclei Templates (1)

Grafana Unauthenticated Snapshot Creation
HIGHby pdteam,bing0o
Shodan: title:"Grafana" || cpe:"cpe:2.3:a:grafana:grafana" || http.title:"grafana"
FOFA: title="grafana" || app="grafana"

References (4)

Core 4
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210513-0007/

Scores

CVSS v3 7.5
EPSS 0.8304
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2026-05-01
Status published
Products (3)
grafana/grafana 6.7.3 - 7.4.1
grafana/grafana 6.7.3 - 7.4.2Go
netapp/e-series_performance_analyzer
Published Mar 18, 2021
Tracked Since Feb 18, 2026