Vulnerability record · CVE-2018-15727 · published 29 August 2018
CVE-2018-15727: Grafana authentication bypass via forged remember-me cookie
Grafana · Grafana
Grafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" cookie knowing only the username of an LDAP or OAuth user. This lets an unauthenticated remote party impersonate a known account without any credential, which is severe for any internet-reachable Grafana instance.
Description
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS percentile, though the flaw is limited to deployments using LDAP or OAuth users.
What it is
Grafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" cookie knowing only the username of an LDAP or OAuth user. This lets an unauthenticated remote party impersonate a known account without any credential, which is severe for any internet-reachable Grafana instance.
Impact
An attacker gains full authenticated access as the targeted user, including that user's dashboards, data sources and, if the account is an administrator, Grafana administrative functions.
Attack surface
Reachable over the network via HTTP requests to the Grafana web interface; no authentication is required and no user interaction is needed, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The attacker only needs to know a valid LDAP or OAuth username.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high at roughly 0.64 (99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Grafana to 4.6.4 or 5.2.3 or later; the vendor advisory and Red Hat errata RHSA-2018:3829 and RHSA-2019:0019 cover the fix.
- If immediate upgrade is not possible, restrict network access to the Grafana interface to trusted networks only.
- Disable or avoid LDAP/OAuth-backed accounts where the deployment does not require them, and review accounts whose usernames are publicly guessable.
- Rotate the Grafana secret key and invalidate existing sessions and remember-me cookies after patching.
- Monitor vendor and Red Hat errata channels for updated packages for any bundled Grafana in Ceph Storage.
Detection
- Search Grafana access logs for successful logins or authenticated API calls that lack a preceding credential-based login for the same user.
- Alert on requests carrying a grafana_session or remember-me cookie from source IPs that have never completed a normal login.
- Baseline normal login source IPs per user and flag authenticated activity from new or unusual addresses.
- Audit Grafana user and admin actions for changes made by accounts whose sessions cannot be tied to a legitimate login event.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105184 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:3829 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0019 | Third Party Advisory |
| https://grafana.com/blog/2018/08/29/grafana-5.2.3-and-4.6.4-released-with-important-security-fix/ | PatchVendor Advisory |
| http://www.securityfocus.com/bid/105184 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:3829 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0019 | Third Party Advisory |
| https://grafana.com/blog/2018/08/29/grafana-5.2.3-and-4.6.4-released-with-important-security-fix/ | PatchVendor Advisory |
Track CVE-2018-15727 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15727), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.