TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Cloud

Over 46,000 Grafana Instances Vulnerable to Account Takeover

Akinola Ajibola by Akinola Ajibola
June 16, 2025
in Cloud, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • DevOps teams have been advised by security researchers to fix a high-severity vulnerability in Grafana, a widely used tool, that may be exposing them to account...
  • Multiple iterations of the open-source platform used to monitor and visualize infrastructure and application metrics are affected by the vulnerability, which is recorded as CVE-2025-4123.
  • Bug bounty hunter Alvaro Balada found the vulnerability, which Grafana Labs fixed in security upgrades published on May 21.

DevOps teams have been advised by security researchers to fix a high-severity vulnerability in Grafana, a widely used tool, that may be exposing them to account takeover attempts as over 46,000 Grafana instances that are visible to the internet are still unpatched and vulnerable to a client-side open redirect vulnerability that permits the execution of a malicious plugin and account takeover.

Multiple iterations of the open-source platform used to monitor and visualize infrastructure and application metrics are affected by the vulnerability, which is recorded as CVE-2025-4123.

Bug bounty hunter Alvaro Balada found the vulnerability, which Grafana Labs fixed in security upgrades published on May 21.

According to researchers from application security firm OX Security, who call the problem “The Grafana Ghost,” as of this writing, approximately one-third of all Grafana instances accessible over the public internet had not been fixed. 

The goal of the analysts’ effort, they told BleepingComputer, was to show that Balada’s discovery could be weaponized.

They evaluated the exposure by comparing the data with the platform’s spread throughout the ecosystem after identifying the versions that were susceptible to the assault.

Of the 128,864 instances they discovered online, 46,506 were still running exploitable versions. This amounts to roughly 36% of the total Grafana instances that are visible to the public, in addition to innumerable Grafana servers that are not online. This was announced on Sunday by  Ox Security and issued a warning about CVE-2025-4123.

DevOps engineers, sysadmins, and developers utilize Grafana, an open source analytics and visualization tool, to keep an eye on infrastructure and system performance.

Through a series of exploitation steps that combine client-side path traversal with open redirect mechanics, OX Security’s thorough analysis of CVE-2025-4123 revealed that attackers can trick victims into clicking URLs that cause a malicious Grafana plugin to load from a site under the threat actor’s control.

The National Vulnerability Database (NVD) describes it as a cross-site scripting (XSS) vulnerability brought on by combining an open redirect with a client path traversal.

Attackers can use this to reroute users to a page that has a frontend plugin installed, which will run arbitrary JavaScript. The XSS will function if anonymous access is enabled, and this vulnerability does not require editing permissions,” it continued.

“A full read SSRF can be accomplished by taking advantage of the open redirect if the Grafana Image Renderer plugin is installed.”

According to Ox Security, a malicious link given to the victim is the first in a series of exploits that compromise the vulnerability.

Also worth reading
Gabon Data Centre Push Shows Africa Digital Sovereignty Is Becoming Infrastructure SAP Cloud Growth Eases Fears That AI Will Weaken Enterprise Software CBN’s Data Localisation Directive Puts Nigerian Fintechs In A Cloud Dilemma Meta Is Becoming a Cloud Computing Company Pinterest & Amazon Deepen Their Ties With $4 Billion Cloud Deal GitHub Confirms Hackers Stole Data From About 3,800 Internal Repositories

The security vendor went on to say, “When the link is clicked, Grafana uses an external malicious plugin hosted on the attacker’s server.”

The researchers claim that the malicious URLs have the potential to cause the user’s browser to run arbitrary JavaScript.

The exploit can work even with anonymous access enabled and doesn’t require escalated privileges.

The vulnerability enables attackers to alter account credentials, take over user sessions, and read internal resources by using server-side request forgery (SSRF) when the Grafana Image Renderer plugin is installed.

Grafana’s default Content Security Policy (CSP) offers some defense, but because client-side enforcement is limited, it cannot stop exploitation.

Through JavaScript routing logic built into Grafana, OX Security’s hack shows that CVE-2025-4123 may be abused client-side and used to go around contemporary browser normalization protections.

This makes account hijacking through password resets simple by enabling attackers to take advantage of URL handling irregularities to load malicious plugins that alter user email addresses.

The large number of exposed instances and the lack of authentication requirements create a significant attack surface, even though CVE-2025-4123 has several exploitation requirements, such as user interaction, an active user session when the victim clicks the link, and having the plugin feature enabled (which is enabled by default).

Grafana administrators are advised to update to versions listed below;
10.4.18+security-01,
11.2.9+security-01,
11.3.6+security-01,
11.4.4+security-01,
11.5.4+security-01,
11.6.1+security-01, and
12.0.0+security-01 in order to reduce the risk of exploitation.

“Any code can be executed by this malicious plugin on the user’s behalf. In this instance, the code that runs causes the victim’s Grafana username and login email to be changed to values that the attacker controls or may reroute to internal services. The attacker can reset the victim’s password and access their Grafana account by using the altered email.

The firm cautioned that hackers could obtain valuable operational data and business intelligence from a vulnerable organization by breaching a Grafana account. If IT teams lose access to vital systems, they may also cause serious operational problems by excluding authorized users, it continued.

According to Ox Security, “the vulnerability affects Grafana instances running locally by crafting a payload that takes advantage of the locally used domain name and port for the local service,” even though it affects a significant portion of Grafana servers that are publicly accessible.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • was-ist-cpanel
    Hackers Are Exploiting Critical cPanel Bug, Putting…
  • MongoDB_Logo
    MongoDB Vulnerability Lets Attackers Crash Servers Remotely
  • post-hero-vulnerability
    Gogs Fixes Critical Zero-Day Bug That Enabled Remote…
  • Cloudflare-AI_Bot-Blocking
    Cloudflare Blames React2Shell Protections for Outage
  • Microsoft SharePoint CTA
    Microsoft Warns of Critical SharePoint Zero-day…
  • microsofts-surface-duo-dualscreen-androi-5f1f3d057e8c350ae07dd862-1-jul-28-2020-15-24-20-poster
    Microsoft Patch Tuesday Fixes 63 Bugs, 1 Zero-Day
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • microsoft-authenticator_fhch
    Critical Vulnerability In Microsoft Authenticator…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Cloud Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: clouddevopsgrafanasecurity
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Samsung Memory Warning Shows AI Chip Shortage May Last Into 2028 August 1, 2026
  • Siri AI Paywall Would Make Apple Intelligence A Services Business July 31, 2026
  • Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA July 31, 2026
  • Snapchat Stops Paying Fully AI-Generated Spotlight Videos As AI Slop Spreads July 31, 2026
  • Anthropic Says Claude Models Breached Real Systems During Cyber Tests July 31, 2026
  • DeepSeek V4 Flash API Raises The Pressure In The AI Agent Price War July 31, 2026
  • MTN Nigeria Fintech Revenue Slump Shows Airtime Lending Risk July 31, 2026
  • Google Earth AI Image Tool Shows How Fake Satellite Proof Could Spread July 31, 2026
  • Lesotho Launches National CSIRT As Cybersecurity Becomes Core Digital Infrastructure July 31, 2026
  • Gabon Data Centre Push Shows Africa Digital Sovereignty Is Becoming Infrastructure July 31, 2026
  • Inforcer Raises $50M As AI Turns Microsoft 365 Security Into An MSP Problem July 31, 2026
  • Rwanda 3G Shutdown Shows Africa Mobile Money Needs A Careful 4G Migration July 31, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.