Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGrafana
APPGrafana9.2.0 – 9.2.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Race Condition
Related vulnerabilities
CVE-2021-39226CRITICAL9.8⚠ KEVPL ✓same product
Grafana – ominięcie uwierzytelnienia i nieuprawniony dostęp do snapshotów
CVE-2026-27876CRITICAL9.1PL ✓same product
RCE w Grafana przez SQL Expressions i plugin Enterprise (CVE-2026-27876)
CVE-2025-41115CRITICAL10.0PL ✓same product
Grafana Enterprise: privilege escalation przez SCIM provisioning (LPE)
CVE-2024-9264CRITICAL9.4PL ✓same product
Grafana: command injection i local file inclusion przez SQL Expressions (duckdb)
CVE-2023-3128CRITICAL9.4PL ✓same product
Grafana: Pominięcie uwierzytelniania przez manipulację emailem w Azure AD OAuth