{"cveID":"CVE-2021-39226","vendorProject":"Grafana Labs","product":"Grafana","vulnerabilityName":"Grafana Authentication Bypass Vulnerability","dateAdded":"2022-08-25","shortDescription":"Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-09-15","knownRansomwareCampaignUse":"Unknown","notes":"https://grafana.com/blog/2021/10/05/grafana-7.5.11-and-8.1.6-released-with-critical-security-fix/; https://nvd.nist.gov/vuln/detail/CVE-2021-39226","cwes":["CWE-287"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-39226","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"auth_bypass","comments":"This authentication bypass vulnerability is exploited by both unauthenticated and authenticated adversaries via the snapshot feature in Grafana. Attackers have leveraged this vulnerability to access and manipulate snapshot data, potentially leading to unauthorized data exposure and loss. Exploitation techniques have not been publicly published. \n\nIn exploitation scenarios, adversaries can view snapshots with the lowest database key by accessing specific paths, such as /dashboard/snapshot/:key or /api/snapshots/:key. If the \"public_mode\" configuration is set to true, unauthenticated users can also delete these snapshots using the path /api/snapshots-delete/:deleteKey. This capability allows attackers to enumerate and delete snapshot data, resulting in complete data loss.","references":["https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/#:~:text=Additionally%2C%20we%20provide%20insight%20into","well%20as%20through%20Cortex%20XDR.&text=Updated%20Sept.","that%20were%20listed%20in%20error.","https://grafana.com/blog/2021/10/05/grafana-7.5.11-and-8.1.6-released-with-critical-security-fix/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-39226","technique":"T1485","technique_name_at_mapping":"Data Destruction","mapping_type":"primary_impact","capability_group":"auth_bypass","comments":"This authentication bypass vulnerability is exploited by both unauthenticated and authenticated adversaries via the snapshot feature in Grafana. Attackers have leveraged this vulnerability to access and manipulate snapshot data, potentially leading to unauthorized data exposure and loss. Exploitation techniques have not been publicly published. \n\nIn exploitation scenarios, adversaries can view snapshots with the lowest database key by accessing specific paths, such as /dashboard/snapshot/:key or /api/snapshots/:key. If the \"public_mode\" configuration is set to true, unauthenticated users can also delete these snapshots using the path /api/snapshots-delete/:deleteKey. This capability allows attackers to enumerate and delete snapshot data, resulting in complete data loss.","references":["https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/#:~:text=Additionally%2C%20we%20provide%20insight%20into","well%20as%20through%20Cortex%20XDR.&text=Updated%20Sept.","that%20were%20listed%20in%20error.","https://grafana.com/blog/2021/10/05/grafana-7.5.11-and-8.1.6-released-with-critical-security-fix/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1485","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data Destruction","name_at_mapping":"Data Destruction","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":20,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}