← Vulnerability feed

Vulnerability record · CVE-2022-31097 · published 15 July 2022

CVE-2022-31097: Grafana Unified Alerting stored XSS allows editor-to-admin privilege escalation

Grafana · Grafana

Grafana 8.x and 9.x branches before 9.0.3, 8.5.9, 8.4.10 and 8.3.10 contain a stored cross-site scripting flaw in the Unified Alerting feature. An attacker with editor privileges can store malicious content that executes in an authenticated admin's browser, escalating their own access to admin. The issue is patched in the listed versions, and disabling alerting or using legacy alerting is a documented workaround.

8.7 CVSS 3.1 High EPSS 69% · top 0.7% CWE-79 · Cross-site scripting
8.7CVSS 3.1 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.7 with scope change and high confidentiality and integrity impact, plus a very high EPSS score, though exploitation requires an authenticated editor and admin user interaction.

What it is

Grafana 8.x and 9.x branches before 9.0.3, 8.5.9, 8.4.10 and 8.3.10 contain a stored cross-site scripting flaw in the Unified Alerting feature. An attacker with editor privileges can store malicious content that executes in an authenticated admin's browser, escalating their own access to admin. The issue is patched in the listed versions, and disabling alerting or using legacy alerting is a documented workaround.

Impact

An attacker gains administrative control of the Grafana instance, which can expose dashboards, data sources and credentials and allow further configuration changes. The CVSS vector rates confidentiality and integrity impact as high with no availability impact.

Attack surface

Reached over the network through the Unified Alerting feature; the attacker needs an authenticated editor account and the victim admin must click a crafted link (UI:R). No unauthenticated path is described.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.686 probability, 99.3rd percentile), indicating elevated likelihood of exploitation. References are release notes and vendor/third-party advisories only, with no public exploit tag.

What to do

  • Upgrade Grafana to 9.0.3, 8.5.9, 8.4.10 or 8.3.10 (or later) as the primary fix.
  • If immediate patching is not possible, disable alerting or switch to legacy alerting as the vendor-documented workaround.
  • Restrict editor accounts to trusted users and review who holds editor privileges.
  • Apply the NetApp advisory guidance for E-Series Performance Analyzer deployments that bundle affected Grafana versions.
  • Monitor Grafana release notes for follow-up fixes on the 8.x and 9.x branches.

Detection

  • Review Grafana audit and application logs for alert rule or alerting configuration changes made by editor accounts.
  • Hunt for suspicious script content or unexpected HTML in stored alert definitions and notification templates.
  • Monitor admin sessions for privilege or role changes originating shortly after an admin clicks an external link.
  • Alert on Grafana versions below 9.0.3, 8.5.9, 8.4.10 or 8.3.10 in asset inventories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31097 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2021-26707Merge-deep project merge-deep prototype pollution vulnerabilityThe merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These …EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2022-31097), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.