← Vulnerability feed

Vulnerability record · CVE-2021-27358 · published 18 March 2021

CVE-2021-27358: Grafana snapshot feature unauthenticated denial of service

Grafana · Grafana

The snapshot feature in Grafana 6.7.3 through 7.4.1 allows an unauthenticated remote attacker to trigger a denial of service through a remote API call when a commonly used configuration is set. Because no authentication is required and the affected versions were widely deployed, any reachable Grafana instance with that configuration is exposed. The record does not specify which configuration setting is required or the exact resource exhausted.

7.5 CVSS 3.1 High EPSS 83% · top 0.3%
7.5CVSS 3.1 base score, v2 5.0
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable denial of service with a very high EPSS score, though limited to availability impact and dependent on an unspecified configuration.

What it is

The snapshot feature in Grafana 6.7.3 through 7.4.1 allows an unauthenticated remote attacker to trigger a denial of service through a remote API call when a commonly used configuration is set. Because no authentication is required and the affected versions were widely deployed, any reachable Grafana instance with that configuration is exposed. The record does not specify which configuration setting is required or the exact resource exhausted.

Impact

An attacker can render the Grafana instance unavailable, disrupting dashboards, alerting and monitoring visibility for defenders. No data confidentiality or integrity impact is described; the effect is availability loss only.

Attack surface

Reached over the network via a Grafana remote API call, with no authentication and no user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Exploitation depends on a commonly used but unspecified configuration being present.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.83042, 99.657th percentile), indicating substantial predicted exploitation activity. References are release notes and vendor/third-party advisories only, with no public exploit tag.

What to do

  • Upgrade Grafana to 7.4.2 or later, which the vendor release notes identify as the fixed version.
  • If immediate upgrade is not possible, restrict network access to the Grafana HTTP API to trusted sources and disable or lock down the snapshot feature.
  • Review the Grafana configuration for the commonly used setting referenced in the advisory and change it to remove the exposure.
  • For NetApp E-Series Performance Analyzer deployments bundling Grafana, apply the NetApp advisory guidance.
  • Monitor Grafana availability and restart or fail over instances that become unresponsive.

Detection

  • Alert on unauthenticated or anomalous requests to Grafana snapshot API endpoints, especially bursts from a single source.
  • Monitor Grafana process health, memory and CPU for sudden spikes or crashes correlated with snapshot API traffic.
  • Review Grafana and reverse-proxy access logs for snapshot-related paths from unexpected or external IP addresses.
  • Track Grafana version inventory to identify instances still running 6.7.3 through 7.4.1.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27358 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2021-26707Merge-deep project merge-deep prototype pollution vulnerabilityThe merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These …EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2021-27358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.