theinfosecnews

CVE-2021-39226

CISA KEV

Published August 25, 2022 · Updated April 3, 2026

high
Official Description+

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

Affected Products

VendorProduct
Grafana LabsGrafana

Patch Status

Patch by 2022-09-15

Recommended Actions

  1. Check if your systems use any of the affected products listed above.
  2. Apply vendor patches immediately if available.
  3. This vulnerability is in CISA's Known Exploited Vulnerabilities catalog — prioritize remediation.
  4. Monitor vendor advisories for updates and additional mitigations.
  5. Review logs for indicators of compromise related to CVE-2021-39226.