Vulnerability record · CVE-2022-26148 · published 21 March 2022
CVE-2022-26148: Grafana Zabbix integration exposes cleartext password in page source
Grafana · Grafana
Grafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can view that page source can read the credentials directly, so the secret is exposed without any cracking or bypass.
Description
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no privileges or interaction required and a high EPSS score, and the flaw directly leaks credentials for a connected monitoring system.
What it is
Grafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can view that page source can read the credentials directly, so the secret is exposed without any cracking or bypass.
Impact
An attacker obtains the Zabbix account password and server URL, gaining authenticated access to the Zabbix monitoring system with the privileges of that account. That access can expose monitored hosts and data and may allow further actions within Zabbix.
Attack surface
Reached over the network via the Grafana web interface when Zabbix integration is enabled; the CVSS vector indicates no privileges and no user interaction are required. The description notes the password is visible in the api_jsonrpc.php source when a user logs in and registration is allowed.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is high (0.534, 98.9th percentile) and references include an Exploit-tagged third-party advisory, indicating public exploit detail exists.
What to do
- Upgrade Grafana past 7.3.4 to a fixed release, or apply the vendor's guidance for the Zabbix integration.
- If upgrading is not immediately possible, disable the Zabbix integration or restrict access to the Grafana instance and the api_jsonrpc.php endpoint.
- Rotate the Zabbix account password and any other credentials that may have been exposed in page source.
- Use a least-privilege Zabbix service account for the Grafana integration so exposed credentials limit damage.
- Review Grafana configuration and page output for other cleartext secrets embedded in HTML or JavaScript.
Detection
- Search Grafana HTTP response bodies and access logs for requests to api_jsonrpc.php and inspect whether credentials appear in returned HTML.
- Monitor Zabbix authentication logs for logins from Grafana server IPs or unexpected source addresses using the integration account.
- Alert on configuration or code changes that place Zabbix credentials in client-visible templates or JavaScript.
- Audit Grafana instances for the Zabbix data source plugin and confirm version and exposure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://2k8.org/post-319.html | ExploitThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20220425-0005/ | Third Party Advisory |
| https://2k8.org/post-319.html | ExploitThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20220425-0005/ | Third Party Advisory |
Track CVE-2022-26148 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26148), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.