Vulnerability record · CVE-2019-15043 · published 3 September 2019
CVE-2019-15043: Grafana HTTP API missing authentication enables denial of service
Grafana · Grafana
Grafana 2.x through 6.x before 6.3.4 leaves parts of its HTTP API accessible without authentication. An unauthenticated remote party can abuse those endpoints to run a denial of service against the Grafana server. The record does not name the specific endpoints involved.
Description
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote availability impact with a high EPSS score, though no KEV listing or documented exploitation.
What it is
Grafana 2.x through 6.x before 6.3.4 leaves parts of its HTTP API accessible without authentication. An unauthenticated remote party can abuse those endpoints to run a denial of service against the Grafana server. The record does not name the specific endpoints involved.
Impact
An attacker can degrade or take down the Grafana server, disrupting dashboards and monitoring for anyone relying on it. No data confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reachable over the network via the Grafana HTTP API, with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any host that can reach the Grafana listener can attempt it.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is high at 0.634 (99th percentile), indicating elevated likelihood of attempted exploitation. References are vendor advisories and release notes only; none are tagged as exploit code.
What to do
- Upgrade Grafana to 6.3.4 or later (5.4.5 for the 5.x line) as directed by the vendor advisory.
- If immediate upgrade is not possible, restrict network access to the Grafana HTTP API to trusted hosts and place it behind an authenticating reverse proxy.
- Review exposed Grafana instances for unnecessary public reachability and remove them from untrusted networks.
- Track vendor release notes for the 6.3.x line and apply subsequent security fixes.
- Monitor Grafana availability and restart or rate-limit if API abuse is observed.
Detection
- Alert on Grafana availability drops, restarts or process crashes without a corresponding maintenance window.
- Baseline and monitor request rates and patterns to unauthenticated Grafana API paths, flagging spikes from single sources.
- Review Grafana and reverse proxy access logs for unauthenticated requests to API endpoints at abnormal volume.
- Correlate Grafana service degradation with source IPs hitting the API to identify abusive clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-15043 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15043), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.