← Vulnerability feed

Vulnerability record · CVE-2019-15043 · published 3 September 2019

CVE-2019-15043: Grafana HTTP API missing authentication enables denial of service

Grafana · Grafana

Grafana 2.x through 6.x before 6.3.4 leaves parts of its HTTP API accessible without authentication. An unauthenticated remote party can abuse those endpoints to run a denial of service against the Grafana server. The record does not name the specific endpoints involved.

7.5 CVSS 3.0 High EPSS 63% · top 0.8% CWE-306 · Missing authentication for critical function
7.5CVSS 3.0 base score, v2 5.0
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote availability impact with a high EPSS score, though no KEV listing or documented exploitation.

What it is

Grafana 2.x through 6.x before 6.3.4 leaves parts of its HTTP API accessible without authentication. An unauthenticated remote party can abuse those endpoints to run a denial of service against the Grafana server. The record does not name the specific endpoints involved.

Impact

An attacker can degrade or take down the Grafana server, disrupting dashboards and monitoring for anyone relying on it. No data confidentiality or integrity impact is described; the effect is availability only.

Attack surface

Reachable over the network via the Grafana HTTP API, with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any host that can reach the Grafana listener can attempt it.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but EPSS is high at 0.634 (99th percentile), indicating elevated likelihood of attempted exploitation. References are vendor advisories and release notes only; none are tagged as exploit code.

What to do

  • Upgrade Grafana to 6.3.4 or later (5.4.5 for the 5.x line) as directed by the vendor advisory.
  • If immediate upgrade is not possible, restrict network access to the Grafana HTTP API to trusted hosts and place it behind an authenticating reverse proxy.
  • Review exposed Grafana instances for unnecessary public reachability and remove them from untrusted networks.
  • Track vendor release notes for the 6.3.x line and apply subsequent security fixes.
  • Monitor Grafana availability and restart or rate-limit if API abuse is observed.

Detection

  • Alert on Grafana availability drops, restarts or process crashes without a corresponding maintenance window.
  • Baseline and monitor request rates and patterns to unauthenticated Grafana API paths, flagging spikes from single sources.
  • Review Grafana and reverse proxy access logs for unauthenticated requests to API endpoints at abnormal volume.
  • Correlate Grafana service degradation with source IPs hitting the API to identify abusive clients.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html
https://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569 Vendor Advisory
https://community.grafana.com/t/release-notes-v6-3-x/19202 Release Notes
https://github.com/grafana/grafana/releases Release Notes
https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/ Release NotesVendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RF5ARGYX3WYB7H2FDR7VAWT
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO4NBL7PKW4OSFRVZENGC42
https://security.netapp.com/advisory/ntap-20191004-0004/
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html
https://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569 Vendor Advisory
https://community.grafana.com/t/release-notes-v6-3-x/19202 Release Notes
https://github.com/grafana/grafana/releases Release Notes
https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/ Release NotesVendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RF5ARGYX3WYB7H2FDR7VAWT
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO4NBL7PKW4OSFRVZENGC42
https://security.netapp.com/advisory/ntap-20191004-0004/

Track CVE-2019-15043 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2020-27846Grafana vulnerabilityA signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th…EPSS 4.9%9.8CVE-2018-15727Grafana authentication bypass via forged remember-me cookieGrafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" c…EPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2019-15043), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.