Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-3128

33
FAUCET Score

CVE-2023-3128 is a critical authentication bypass vulnerability affecting Grafana when configured with Azure AD OAuth using a multi-tenant application. It arises because Grafana validates Azure AD accounts based on the easily modifiable and non-unique email claim, allowing for account takeover. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.7.0, < 8.5.27CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
>= 6.7.0, < 8.5.27CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
>= 9.2.0, < 9.2.20CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
>= 9.2.0, < 9.2.20CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
>= 9.3.0, < 9.3.16CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.4CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.00%
Probability of exploitation in next 30 days
EPSS Percentile
89.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0399 is in the 82nd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 9.4.13
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 9.3.16
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 9.2.20
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 8.5.27
nodejspatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana-0:9.0.9-3.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: ceph-2:18.2.1-194.el8cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana-0:9.2.10-7.el8_9
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

goGHSA-mpv3-g8m3-3fjccritical

Grafana vulnerable to Authentication Bypass by Spoofing

Jun 22, 2023
redhatCVE-2023-3128Moderate

grafana: account takeover possible when using Azure AD OAuth

Jun 22, 2023
zimbrallm-zimbra-2822e7f5b13ba522CRITICAL

Authentication Bypass in Azure AD OAuth in Grafana

Jun 22, 2023
kenticollm-kentico-266d44a07daff49eCRITICAL

Authentication Bypass in Azure AD OAuth in Grafana

Jun 22, 2023
chainsafellm-chainsafe-23c306c2eb029a4eCRITICAL

Authentication Bypass in Azure AD OAuth in Grafana

Jun 22, 2023
apollographqlllm-apollographql-c4209891bdd6b715CRITICAL

Authentication Bypass in Azure AD OAuth in Grafana

Jun 22, 2023
jenkinsllm-jenkins-fb5fd02ef5b1c99cCRITICAL

Authentication Bypass in Azure AD OAuth in Grafana

Jun 22, 2023
nodejsllm-nodejs-54d957f37e49f466CRITICAL

Authentication Bypass in Azure AD OAuth in Grafana

Jun 22, 2023

References

github.com / grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp
Vendor Advisory
grafana.com / security/security-advisories/cve-2023-3128
Vendor Advisory
security.netapp.com / advisory/ntap-20230714-0004
Third Party Advisory