CVE-2021-39226 is a critical vulnerability affecting Grafana versions prior to 8.1.6 and 7.5.11, allowing unauthenticated and authenticated users to view and delete Grafana snapshots. This flaw enables a complete traversal and deletion of all snapshot data, leading to data loss. With a CVSS score of 7.3 (High), the vulnerability is easily exploitable over the network with low attack complexity, impacting confidentiality, integrity, and availability. This CVE is actively exploited in the wild, listed in CISA's KEV catalog, and has high community discussion, with Nuclei templates available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.11CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.1.6CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.