← Vulnerability feed

Vulnerability record · CVE-2022-26148 · published 21 March 2022

CVE-2022-26148: Grafana Zabbix integration exposes cleartext password in page source

Grafana · Grafana

Grafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can view that page source can read the credentials directly, so the secret is exposed without any cracking or bypass.

9.8 CVSS 3.1 Critical EPSS 53% · top 1.0% CWE-312 · Cleartext storage of sensitive data
9.8CVSS 3.1 base score, v2 7.5
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no privileges or interaction required and a high EPSS score, and the flaw directly leaks credentials for a connected monitoring system.

What it is

Grafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can view that page source can read the credentials directly, so the secret is exposed without any cracking or bypass.

Impact

An attacker obtains the Zabbix account password and server URL, gaining authenticated access to the Zabbix monitoring system with the privileges of that account. That access can expose monitored hosts and data and may allow further actions within Zabbix.

Attack surface

Reached over the network via the Grafana web interface when Zabbix integration is enabled; the CVSS vector indicates no privileges and no user interaction are required. The description notes the password is visible in the api_jsonrpc.php source when a user logs in and registration is allowed.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is high (0.534, 98.9th percentile) and references include an Exploit-tagged third-party advisory, indicating public exploit detail exists.

What to do

  • Upgrade Grafana past 7.3.4 to a fixed release, or apply the vendor's guidance for the Zabbix integration.
  • If upgrading is not immediately possible, disable the Zabbix integration or restrict access to the Grafana instance and the api_jsonrpc.php endpoint.
  • Rotate the Zabbix account password and any other credentials that may have been exposed in page source.
  • Use a least-privilege Zabbix service account for the Grafana integration so exposed credentials limit damage.
  • Review Grafana configuration and page output for other cleartext secrets embedded in HTML or JavaScript.

Detection

  • Search Grafana HTTP response bodies and access logs for requests to api_jsonrpc.php and inspect whether credentials appear in returned HTML.
  • Monitor Zabbix authentication logs for logins from Grafana server IPs or unexpected source addresses using the integration account.
  • Alert on configuration or code changes that place Zabbix credentials in client-visible templates or JavaScript.
  • Audit Grafana instances for the Zabbix data source plugin and confirm version and exposure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26148 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3961Samba path traversal vulnerabilityA path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…EPSS 2.4%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2022-26148), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.