References https://loudongyun.360.net/leakDetail/4416caKhYSk%3D https://cn-sec.com/archives/4006911.html https://www.dptech.com/index.php?m=content&c=index&a=show&catid=75&id=5404 https://grafana.com/security/security-advisories/cve-2026-21721/ https://www.ithome.com.tw/news/172424 https://grafana.com/security/security-advisories/cve-2025-3580/ https://cloud.tencent.com/developer/article/2614458 https://m.freebuf.com/articles/458502.html https://www.sentinelone.com/vulnerability-database/cve-2026-21725/ https://www.invicti.com/web-application-vulnerabilities/grafana-improper-authorization-vulnerability-cve-2026-21724
Related VulnerabilitiesPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessGrafana /api/ds/query DuckDB SQL 注入漏洞(CVE-2024-9264)Grafana Dashboard 权限管理不当漏洞PoCgrafana-unauth-access: Grafana Unauthenticated AccessPoCgrafana-metrics-exposure: Grafana Metrics Endpoint - Information DisclosureGrafana Image Renderer 插件 需授权 文件上传限制不当漏洞 可导致远程代码执行Grafana存在重定向漏洞(CVE-2025-4123)Grafana /avatar 服务器端请求伪造漏洞(CVE-2020-13379)PoCCVE-2019-15043: Grafana - Improper Access ControlPoCCVE-2020-11110: Grafana <= 6.7.1 - Cross-Site ScriptingPoCCVE-2020-13379: Grafana 3.0.1-7.0.1 - Server-Side Request Forgery