Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-39226

97
FAUCET Score

CVE-2021-39226 is a critical vulnerability affecting Grafana versions prior to 8.1.6 and 7.5.11, allowing unauthenticated and authenticated users to view and delete Grafana snapshots. This flaw enables a complete traversal and deletion of all snapshot data, leading to data loss. With a CVSS score of 7.3 (High), the vulnerability is easily exploitable over the network with low attack complexity, impacting confidentiality, integrity, and availability. This CVE is actively exploited in the wild, listed in CISA's KEV catalog, and has high community discussion, with Nuclei templates available for detection.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.5.11CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 8.0.0, < 8.1.6CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.89%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Aug 25, 2022
Nuclei: CVE-2021-39226 · Nov 30, 2021
This CVE's current EPSS score of 0.9989 is in the 100th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 7.5.11
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 8.1.6
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana-0:7.3.6-3.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: grafana-0:6.2.2-7.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: grafana-0:6.3.6-3.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/grafana:v3.11.784-1.g423963f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.10Fixed in: openshift4/ose-grafana:v4.10.0-202202160023.p0.g48aec35.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-grafana:v4.6.0-202208310224.p0.gcf170c0.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift4/ose-grafana:v4.7.0-202208310205.p0.g613acad.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: openshift4/ose-grafana:v4.8.0-202208311019.p0.gf98b47f.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.9Fixed in: openshift4/ose-grafana:v4.9.0-202208311003.p0.g3b7bed6.assembly.stream
View patch
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-grafana
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 2Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 3Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 3Fixed in: grafana-container
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: rhceph/rhceph-4-dashboard-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: grafana

Vendor Advisories (2)

goGHSA-69j6-29vr-p3j9high

Authentication bypass for viewing and deletions of snapshots

Oct 5, 2021
redhatCVE-2021-39226Important

grafana: Snapshot authentication bypass

Oct 5, 2021

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
github.com / grafana/grafana/commit/2d456a6375855364d098ede379438bf7f0667269
Patch
github.com / grafana/grafana/security/advisories/GHSA-69j6-29vr-p3j9
ExploitMitigationVendor Advisory
grafana.com / docs/grafana/latest/release-notes/release-notes-7-5-11
Release Notes
grafana.com / docs/grafana/latest/release-notes/release-notes-8-1-6
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DCKBFUSY6V4VU5AQUYWKISREZX5NLQJT
Broken Link
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/E6ANHRDBXQT6TURLP2THM26ZPDINFBEG
Broken Link
security.netapp.com / advisory/ntap-20211029-0008
Third Party Advisory
openwall.com / lists/oss-security/2021/10/05/4
Mailing ListThird Party Advisory