← Vulnerability feed

Vulnerability record · CVE-2021-43798 · published 7 December 2021

CVE-2021-43798: Grafana plugin path directory traversal allows local file read

Grafana · Grafana

Grafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local files on the host. The flaw was exploited as a zero-day before patched versions 8.0.7, 8.1.8, 8.2.7 and 8.3.1 were released, and it exposes configuration and secret material that can enable further compromise.

7.5 CVSS 3.1 High CISA KEV since 9 Oct 2025 EPSS 89% · top 0.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
89%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
17References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote file read with confirmed exploitation, KEV listing and very high EPSS probability makes this an urgent patch target.

What it is

Grafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local files on the host. The flaw was exploited as a zero-day before patched versions 8.0.7, 8.1.8, 8.2.7 and 8.3.1 were released, and it exposes configuration and secret material that can enable further compromise.

Impact

An attacker can read arbitrary files on the Grafana server, including configuration files that may hold database credentials, API keys and other secrets. This can lead to lateral movement or full compromise of connected systems.

Attack surface

Reachable over the network through the Grafana HTTP endpoint at /public/plugins// with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any installed plugin ID can be used in the path.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-10-09, and EPSS gives a 30-day probability of 0.885 (99.8th percentile). Public exploit code is referenced in the Packet Storm entries tagged Exploit.

What to do

  • Upgrade Grafana to 8.0.7, 8.1.8, 8.2.7 or 8.3.1 (or later) immediately.
  • If patching is not possible, restrict network access to the Grafana HTTP interface to trusted users and networks.
  • Rotate any credentials, API keys or secrets stored in Grafana configuration files that may have been exposed.
  • Follow the vendor advisory GHSA-8pjx-jj86-j47p and CISA KEV required action guidance, including discontinuing use if mitigations are unavailable.

Detection

  • Search web access logs for requests to /public/plugins/ containing traversal sequences such as ../ or encoded variants.
  • Alert on HTTP 200 responses to plugin paths that include path traversal patterns.
  • Monitor for unusual outbound connections or authentication attempts using credentials harvested from Grafana config files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-43798 to the Known Exploited Vulnerabilities catalog on 9 October 2025 as "Grafana Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 October 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/165221/Grafana-8.3.0-Directory-Traversal-Arbitrary-File-Read.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2021/12/09/2 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/4 Mailing ListPatchThird Party Advisory
https://github.com/grafana/grafana/commit/c798c0e958d15d9cc7f27c72113d572fa58545ce PatchThird Party Advisory
https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p PatchVendor Advisory
https://grafana.com/blog/2021/12/08/an-update-on-0day-cve-2021-43798-grafana-directory-traversal/ Vendor Advisory
https://security.netapp.com/advisory/ntap-20211229-0004/ Third Party Advisory
http://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/165221/Grafana-8.3.0-Directory-Traversal-Arbitrary-File-Read.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2021/12/09/2 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/4 Mailing ListPatchThird Party Advisory
https://github.com/grafana/grafana/commit/c798c0e958d15d9cc7f27c72113d572fa58545ce PatchThird Party Advisory
https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p PatchVendor Advisory
https://grafana.com/blog/2021/12/08/an-update-on-0day-cve-2021-43798-grafana-directory-traversal/ Vendor Advisory
https://security.netapp.com/advisory/ntap-20211229-0004/ Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-43798 US Government Resource

Track CVE-2021-43798 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2020-27846Grafana vulnerabilityA signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th…EPSS 4.9%9.8CVE-2018-15727Grafana authentication bypass via forged remember-me cookieGrafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" c…EPSS 64%analysed9.4CVE-2024-9264Grafana SQL Expressions feature allows command injection and file readGrafana's experimental SQL Expressions feature evaluates duckdb queries containing user input without sufficient sanitization, enabling command injec…EPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2021-43798), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.