LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-43798: Grafana Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 9, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 30, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-43798 to its Known Exploited Vulnerabilities catalog on Oct 9, 2025, with a federal patch deadline of Oct 30, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Grafana contains a path traversal vulnerability that could allow access to local files.

CVE-2021-43798 is a path traversal vulnerability in Grafana Labs Grafana that can allow unauthorized access to local files on the host system. For IT and security teams, this matters because Grafana is commonly used for monitoring and dashboards; successful abuse could expose configuration files, credentials, or other sensitive data stored on the server, increasing the risk of further compromise.

Public detail is limited to the CISA summary describing a path traversal issue that could allow access to local files. Confirm all specifics, including affected versions and exact impact, against the vendor advisory before acting.

How it works

This issue falls under CWE-22, improper limitation of a pathname to a restricted directory (path traversal). In products of this class, an attacker can craft requests that include directory traversal sequences to escape the intended file access boundaries and read files outside the application’s permitted scope.

An attacker who can reach the vulnerable Grafana instance would abuse the flaw by supplying specially formed input that the application fails to sanitize properly, resulting in retrieval of local files. No further exploit mechanics are provided in the available facts; treat any observed behavior as potentially leading to information disclosure and investigate accordingly. Confirm the precise attack surface and request patterns against the vendor advisory.

Am I affected? How to find it in your systems

Grafana typically runs as a web-accessible service on servers or in containers used for observability, often listening on common ports and integrated into monitoring stacks. Inventory efforts should focus on identifying all Grafana deployments across on-premises, cloud, and container environments.

For signs of exploitation, examine web server and application logs for anomalous path requests containing traversal sequences or unexpected file access attempts. Correlate with authentication logs and file system access telemetry. Absence of known ransomware use is documented, but treat any confirmed access as a potential precursor to broader compromise.

How to remediate

Prioritize applying the vendor-provided update or mitigations named in the official Grafana Labs advisory for CVE-2021-43798. Follow the CISA required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Document the remediation and re-scan to confirm closure.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls appropriate to a path traversal weakness in a web-facing monitoring application.

These steps buy time but do not replace the official fix.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to breaches through unauthorized file access. If you suspect exploitation, treat any retrieved local files as potentially compromised, rotate credentials that may have been stored on the host, and conduct a full incident response review. Readers can run a free exposure scan of their email addresses to check whether those addresses appear in known breach data sets as an additional hygiene step.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGrafana Labs · Grafana
WeaknessCWE-22
Added to CISA KEVOct 9, 2025
Federal patch deadlineOct 30, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities