Record summary

CVE-2021-27358 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 1, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

github.com/grafana/grafana

Browse Go / github.com/grafana/grafana
GitHub Advisory6.7.3 to < 7.4.2 · Fixed in 7.4.2affected

Nuclei templates

1
ProjectDiscoveryHIGHGrafana Unauthenticated Snapshot CreationCVSS 7.5

Grafana 6.7.3 through 7.4.1 snapshot functionality can allow an unauthenticated remote attacker to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

Impact

An attacker can create snapshots of sensitive data without authentication, potentially leading to unauthorized access and data exposure.

Remediation

Upgrade to the latest version of Grafana that includes a fix for CVE-2021-27358 or apply the provided patch to mitigate the vulnerability.

WeaknessesCWE-306
Authorspdteam, bing0o
Template tagscve2021cvegrafanaunauthvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Shodan: title:"Grafana"
Shodan: cpe:"cpe:2.3:a:grafana:grafana"
Shodan: http.title:"grafana"
FOFA: title="grafana"
FOFA: app="grafana"
Google: intitle:"grafana"

Source: ProjectDiscovery

References

5