References https://grafana.com/security/security-advisories/cve-2026-21721/ https://loudongyun.360.net/leakDetail/4416caKhYSk%3D https://cn-sec.com/archives/4006911.html https://www.dptech.com/index.php?m=content&c=index&a=show&catid=75&id=5404 https://grafana.com/security/security-advisories/cve-2025-3260/ https://www.invicti.com/web-application-vulnerabilities/grafana-incorrect-authorization-vulnerability-cve-2026-21721 https://www.sentinelone.com/vulnerability-database/cve-2025-3260/ https://unit42.paloaltonetworks.com/new-bola-vulnerability-grafana/ https://www.tenablecloud.cn/plugins/was/114842 https://stack.chaitin.com/vuldb/detail/b6ac5e57-38fe-4671-9710-9696c2f80448
Related VulnerabilitiesPoCCVE-2026-44343: WGDashboard < 4.3.2 - Unauthenticated File ReadPoCCVE-2026-59177: ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard AccessPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessPoCCVE-2026-15733: WGDashboard <= 4.3.2 - Authenticated OS Command Injection /etc/passwd ReadPoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path TraversalPoCtrino-unauth-cluster: Trino Cluster Overview - Unauthenticated Dashboard ExposureKubernetes Dashboard /api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs 权限绕过漏洞(CVE-2018-18264)Grafana /api/ds/query DuckDB SQL 注入漏洞(CVE-2024-9264)Nezha Dashboard /dashboard../data/config.yaml 目录遍历漏洞(CVE-2026-53519)PoClaravel-pulse-unauth: Laravel Pulse - Unauthenticated Dashboard AccessPoCpuppetdb-dashboard-unauth: PuppetDB Dashboard - Unauthenticated AccessKubeflow Dashboard /api/workgroup/env-info 未授权访问漏洞PoCapache-skywalking-dashboard: Apache SkyWalking - Dashboard