CVE-2021-43798Active Exploitation(grafana / grafana)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for grafana grafana systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-10-10)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
grafana

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-19: 1Mentions · 2026-03-15: 1Mentions · 2026-03-23: 1Mentions · 2026-10-10: 2PoC Mentioned / Linked · 2026-03-15: 1Active Exploitation · 2026-02-19: 102-1903-1503-2310-10
Signal classification3 categories
Active Exploitation
133.3%
Exploit
133.3%
General
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-191
Active Exploitation1
2026-03-151
Exploit1
2026-03-231
General1
Full discourse5 posts
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2021-43798 Entity: Grafana Lineage: Public vulnerability → Public exploit/PoC → Observed exploitation Relationship: - Grafana → CVE-2021-43798 → Evidence → Operational Risk Current State: DISCLOSED, POC_AVAILABLE, ACTIVE_EXPLOITATION

    1000019
    8 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2021-43798 Product: Grafana Labs / Grafana Summary: VulnCheck reports real-world exploitation activity affecting Grafana Labs / Grafana. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 02 Dec 2023 Source: https://vulncheck.com/xdb/558378a73ba5 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Grafana #CVE_2021_43798 #ActiveExploitation #Exploit

    0000025
    229 followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2021-43798 (EPSS 94.00%) Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vuln Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2021-43798 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The tweet briefly notes CVE-2021-43798 with a high EPSS score, stating it affects Grafana versions 8.0.0-beta1 through 8.3.0 and that patched versions mitigate the vulnerability.

    0000049
    310 followersView on X
  • Havij@_havij
    Exploit

    Exploiting Grafana (CVE-2021-43798) To Gain SSH Access and Extract Secrets From a Kubernetes Cluster Link: https://meetcyber.net/kubernetes-for-everyone-exploiting-grafana-cve-2021-43798-to-gain-ssh-access-and-extract-c3f02bb2ff8b #exploitgrafana #cve2021 #exploitkubernetes #pentest

    Post summary

    The post claims to exploit Grafana CVE‑2021‑43798 to gain SSH access and harvest secrets from a Kubernetes cluster, but it offers no evidence of active attacks, patch info, or detailed code.

    0000029
    27 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Early 2026 reports show rising cloud compromises via misconfigured services and CVE-2023-3519, CVE-2023-2868, CVE-2021-43798 exploitation, expanding victim impact across sectors. #CloudSecurity https://threatcluster.io/cluster/cloud-compromise-driven-by-security-tool-misuse-and-vulnerab-c2addaf1

    Post summary

    Reports indicate that CVE-2023-3519, CVE-2023-2868, and CVE-2021-43798 are actively exploited in cloud environments, leading to widespread compromises across multiple sectors.

    0000064
    71 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---
Appgrafanagrafana8.0.0--
Appgrafanagrafana8.0.0--
Appgrafanagrafana8.0.0--
Appgrafanagrafana8.3.0--

Explore more