Junglewise Threat Intelligence

CVE-2021-39226: Authentication bypass for viewing and deletions of snapshots

CVE-2021-39226 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2021-10-05

Vendors: Grafana Labs.

Executive brief

Grafana contains an authentication bypass vulnerability where unauthenticated and authenticated users can view or delete snapshot data by accessing specific literal API paths. This occurs because the application fails to properly authorize access to snapshots with the lowest database keys, potentially leading to complete data loss.

Affected products

  • Grafana Labs Grafana < 7.5.11, < 8.1.6

Timeline

  • 2021-10-05: disclosed: Public disclosure via oss-security mailing list
  • 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-25: advisory: NVD publication date
  • 2021-10-05: patched: Fixes released in versions 8.1.6 and 7.5.11
  • exploited: Reported as exploited in the wild by CISA and other sources.

Related threats