← Vulnerability feed

Vulnerability record · CVE-2018-15727 · published 29 August 2018

CVE-2018-15727: Grafana authentication bypass via forged remember-me cookie

Grafana · Grafana

Grafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" cookie knowing only the username of an LDAP or OAuth user. This lets an unauthenticated remote party impersonate a known account without any credential, which is severe for any internet-reachable Grafana instance.

9.8 CVSS 3.0 Critical EPSS 64% · top 0.8% CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 7.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS percentile, though the flaw is limited to deployments using LDAP or OAuth users.

What it is

Grafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" cookie knowing only the username of an LDAP or OAuth user. This lets an unauthenticated remote party impersonate a known account without any credential, which is severe for any internet-reachable Grafana instance.

Impact

An attacker gains full authenticated access as the targeted user, including that user's dashboards, data sources and, if the account is an administrator, Grafana administrative functions.

Attack surface

Reachable over the network via HTTP requests to the Grafana web interface; no authentication is required and no user interaction is needed, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The attacker only needs to know a valid LDAP or OAuth username.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high at roughly 0.64 (99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Grafana to 4.6.4 or 5.2.3 or later; the vendor advisory and Red Hat errata RHSA-2018:3829 and RHSA-2019:0019 cover the fix.
  • If immediate upgrade is not possible, restrict network access to the Grafana interface to trusted networks only.
  • Disable or avoid LDAP/OAuth-backed accounts where the deployment does not require them, and review accounts whose usernames are publicly guessable.
  • Rotate the Grafana secret key and invalidate existing sessions and remember-me cookies after patching.
  • Monitor vendor and Red Hat errata channels for updated packages for any bundled Grafana in Ceph Storage.

Detection

  • Search Grafana access logs for successful logins or authenticated API calls that lack a preceding credential-based login for the same user.
  • Alert on requests carrying a grafana_session or remember-me cookie from source IPs that have never completed a normal login.
  • Baseline normal login source IPs per user and flag authenticated activity from new or unusual addresses.
  • Audit Grafana user and admin actions for changes made by accounts whose sessions cannot be tied to a legitimate login event.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15727 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2021-20236Zeromq classic buffer overflow vulnerabilityA flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2018-15727), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.