CVE-2021-27358
Denial of service in Grafana
Record summary
CVE-2021-27358 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 1, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | 6.7.3 to < 7.4.2 · Fixed in 7.4.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHGrafana Unauthenticated Snapshot CreationCVSS 7.5
Grafana 6.7.3 through 7.4.1 snapshot functionality can allow an unauthenticated remote attacker to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
Impact
An attacker can create snapshots of sensitive data without authentication, potentially leading to unauthorized access and data exposure.
Remediation
Upgrade to the latest version of Grafana that includes a fix for CVE-2021-27358 or apply the provided patch to mitigate the vulnerability.
Source: ProjectDiscovery