CVE-2026-81841: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-81841 is a missing authorization vulnerability in Grafana OSS and Grafana Enterprise affecting the shared (public) dashboard feature. When a shared dashboard is paused, its access token is not revoked for the frontend bootstrap data endpoints, allowing anyone with the dashboard link to retrieve data source configurations and stored credentials without authentication. The vulnerability was published on September 29, 2026, and affects Grafana versions 11.6.0–11.6.17, 12.0.0–12.0.10, 12.1.0–12.1.10, 12.2.0–12.2.11, 12.3.0–12.3.11, 12.4.0–12.4.11, 13.0.0–13.0.9, 13.1.0–13.1.6, and 13.2.0–13.2.2. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Grafana Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): when a shared dashboard is paused, Grafana fails to invalidate the associated access token for the API endpoints that serve frontend bootstrap data. An attacker who possesses the shared dashboard URL can send unauthenticated HTTP requests to these bootstrap endpoints and receive the full data source configuration, including stored credentials for data sources configured with browser-access mode. Notably, deleting the shared dashboard does properly revoke the token, confirming the flaw is specific to the pause operation's token lifecycle management (GitHub Advisory, Grafana Advisory).

Impact

Successful exploitation allows an unauthenticated attacker holding a paused shared dashboard link to retrieve the configuration of the dashboard's data sources, including stored credentials for data sources using browser access mode. This constitutes a confidentiality breach that could expose database passwords, API keys, or other sensitive credentials stored within Grafana data source configurations. While integrity and availability are not directly impacted, exposed credentials could enable lateral movement into backend systems connected to those data sources (GitHub Advisory, Grafana Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Grafana Advisory). The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability is automatable (no user interaction required) and requires no authentication, only possession of a paused shared dashboard URL. It has not been added to the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Obtain the shared dashboard URL: Acquire the link to a Grafana shared (public) dashboard that has been paused — this could be obtained via phishing, accidental exposure, or prior access to the Grafana instance.
  2. Identify bootstrap data endpoints: Using the shared dashboard token embedded in the URL, identify the frontend bootstrap API endpoints (e.g., /api/frontend/settings or similar bootstrap endpoints served to the shared dashboard context).
  3. Send unauthenticated request: Issue an HTTP GET request to the bootstrap endpoint using the shared dashboard's access token, without providing any authentication credentials.
  4. Retrieve data source configuration: Parse the response to extract data source configurations, including connection strings, usernames, passwords, or API keys stored for browser-accessible data sources.
  5. Leverage exposed credentials: Use the harvested credentials to access backend data sources (databases, APIs, etc.) directly, enabling further lateral movement or data exfiltration (GitHub Advisory, Grafana Advisory).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to Grafana frontend bootstrap endpoints (e.g., /api/frontend/settings, /api/ds/query) originating from unexpected IP addresses using a shared dashboard token associated with a paused dashboard.
  • Logs: Grafana access logs showing requests to bootstrap/data source configuration endpoints with a shared dashboard token where the dashboard status is "paused"; repeated access from external or unknown IPs using the same token after the dashboard was paused.
  • Application: Grafana audit logs (if enabled) recording data source configuration reads without an authenticated user session, attributed to a shared dashboard token.

Mitigation and workarounds

Grafana has released patched versions addressing this vulnerability. Users should upgrade to: 11.6.18+, 12.0.11+, 12.1.11+, 12.2.12+, 12.3.12+, 12.4.12+, 13.0.10+, 13.1.7+, or 13.2.3+. As an immediate workaround, delete (rather than pause) shared dashboards that are no longer needed, since deletion properly revokes the access token. Additionally, review Grafana access logs for unauthorized access to paused shared dashboards, restrict dashboard sharing to trusted recipients, and audit data source credentials that may have been exposed (Grafana Advisory, GitHub Advisory).

Community reactions

The vulnerability was disclosed by Grafana's security team on September 29, 2026, with a corresponding GitHub Advisory (GHSA-4jjr-w7m9-wx5q) published the same day. Community tracking was noted on Bluesky and various CVE aggregator platforms shortly after disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database entries (GitHub Advisory, Grafana Advisory).

Additional resources


Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-102276HIGH7.5
  • JavaScript logoJavaScript
  • sgx-enclave-latest-tdqe-unsigned
NoYesSep 28, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-81841MEDIUM5.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesSep 29, 2026
CVE-2026-81842MEDIUM4.3
  • Grafana logoGrafana
  • grafana
NoYesSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management