August 25, 2022 · Applied Cybernetics Group
CVE-2021-39226 — Grafana Labs Grafana
Grafana Authentication Bypass Vulnerability
- Added to KEV
2022-08-25- Federal due date
2022-09-15- Vendor
- Grafana Labs
- Product
- Grafana
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-39226
CISA short description
Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.
Required action
Apply updates per vendor instructions.