CVE-2022-39306High· 8.1▾ TwilightAn authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.8%
Last analysed / modified upstream
6.4 → 8.1
medium → high
An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup link. The highest impacts to the system are confidentiality and integrity.
grafana: email addresses and usernames cannot be trusted — rated Moderate by Red Hat. Released 2022-11-08, updated 2026-09-17.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420
Affected packages:
github.com/grafana/grafana >= 8.0.0, < 8.5.15github.com/grafana/grafana >= 9.0.0, < 9.2.4Patched in:
github.com/grafana/grafana 8.5.15github.com/grafana/grafana 9.2.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-39324Medium· 6.7grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)
CVE-2022-39307Medium· 5.3grafana: User enumeration via forget password (CVE-2022-39307)
CVE-2026-42308Medium· 6.2Pillow: Pillow: Denial of Service via integer overflow in font processing (CVE-2026-42308)
CVE-2026-46595High· 7.1golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)
CVE-2026-73646High· 7.5PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree
CVE-2026-89665High· 7.0kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE (CVE-2026-89665)