Vulnerability record · CVE-2021-27358 · published 18 March 2021
CVE-2021-27358: Grafana snapshot feature unauthenticated denial of service
Grafana · Grafana
The snapshot feature in Grafana 6.7.3 through 7.4.1 allows an unauthenticated remote attacker to trigger a denial of service through a remote API call when a commonly used configuration is set. Because no authentication is required and the affected versions were widely deployed, any reachable Grafana instance with that configuration is exposed. The record does not specify which configuration setting is required or the exact resource exhausted.
Description
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated network-reachable denial of service with a very high EPSS score, though limited to availability impact and dependent on an unspecified configuration.
What it is
The snapshot feature in Grafana 6.7.3 through 7.4.1 allows an unauthenticated remote attacker to trigger a denial of service through a remote API call when a commonly used configuration is set. Because no authentication is required and the affected versions were widely deployed, any reachable Grafana instance with that configuration is exposed. The record does not specify which configuration setting is required or the exact resource exhausted.
Impact
An attacker can render the Grafana instance unavailable, disrupting dashboards, alerting and monitoring visibility for defenders. No data confidentiality or integrity impact is described; the effect is availability loss only.
Attack surface
Reached over the network via a Grafana remote API call, with no authentication and no user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Exploitation depends on a commonly used but unspecified configuration being present.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.83042, 99.657th percentile), indicating substantial predicted exploitation activity. References are release notes and vendor/third-party advisories only, with no public exploit tag.
What to do
- Upgrade Grafana to 7.4.2 or later, which the vendor release notes identify as the fixed version.
- If immediate upgrade is not possible, restrict network access to the Grafana HTTP API to trusted sources and disable or lock down the snapshot feature.
- Review the Grafana configuration for the commonly used setting referenced in the advisory and change it to remove the exposure.
- For NetApp E-Series Performance Analyzer deployments bundling Grafana, apply the NetApp advisory guidance.
- Monitor Grafana availability and restart or fail over instances that become unresponsive.
Detection
- Alert on unauthenticated or anomalous requests to Grafana snapshot API endpoints, especially bursts from a single source.
- Monitor Grafana process health, memory and CPU for sudden spikes or crashes correlated with snapshot API traffic.
- Review Grafana and reverse-proxy access logs for snapshot-related paths from unexpected or external IP addresses.
- Track Grafana version inventory to identify instances still running 6.7.3 through 7.4.1.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/grafana/grafana/blob/master/CHANGELOG.md | Release NotesThird Party Advisory |
| https://github.com/grafana/grafana/blob/master/CHANGELOG.md#742-2021-02-17 | Release NotesThird Party Advisory |
| https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/ | Release NotesVendor Advisory |
| https://security.netapp.com/advisory/ntap-20210513-0007/ | Third Party Advisory |
| https://github.com/grafana/grafana/blob/master/CHANGELOG.md | Release NotesThird Party Advisory |
| https://github.com/grafana/grafana/blob/master/CHANGELOG.md#742-2021-02-17 | Release NotesThird Party Advisory |
| https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/ | Release NotesVendor Advisory |
| https://security.netapp.com/advisory/ntap-20210513-0007/ | Third Party Advisory |
Track CVE-2021-27358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.