CVE-2023-3128Critical· 9.4▾ AbyssalPoC availableGrafana vulnerable to Authentication Bypass by Spoofing
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 51.7 · likelihood 0.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
4.1%
1 GitHub repo
Grafana is validating Azure AD accounts based on the email claim.
On Azure AD, the profile email field is not unique and can be easily modified.
This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
github.com/grafana/grafana >= 9.4.0, < 9.4.13github.com/grafana/grafana >= 9.3.0, < 9.3.16github.com/grafana/grafana >= 9.0.0, < 9.2.20github.com/grafana/grafana < 8.5.27Upgrade to a patched release:
github.com/grafana/grafana 9.4.13github.com/grafana/grafana 9.3.16github.com/grafana/grafana 9.2.20github.com/grafana/grafana 8.5.27Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-3415Medium· 4.3Grafana's insecure DingDing Alert integration exposes sensitive information
CVE-2021-43798High· 7.5Grafana path traversal
CVE-2021-39226High· 7.3Authentication bypass for viewing and deletions of snapshots
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2020-13430Medium· 6.1Grafana XSS via the OpenTSDB datasource
CVE-2024-10452Low· 2.2Grafana org admin can delete pending invites in different org