Site icon TheCyberThrone

CISA Adds Grafana CVE-2021-43798 to KEV

Advertisements

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included Grafana CVE-2021-43798 in its Known Exploited Vulnerabilities (KEV) catalog in October 2025, signalling to organizations that this long-standing security flaw continues to pose a real-world threat.

Background: What is CVE-2021-43798?

CVE-2021-43798 is a directory traversal vulnerability affecting Grafana—one of the industry’s most widely deployed open-source observability platforms. Versions 8.0.0-beta1 through 8.3.0 are at risk, allowing attackers to craft HTTP requests that exploit the /public/plugins/<plugin-id>/ path. With no authentication required, attackers can access files outside of allowed directories, including sensitive system and application data.

Attack Impact and Exploitation Trends

Why Did CISA Add This CVE to KEV?

The KEV catalog prioritizes vulnerabilities with confirmed, observed exploitation in the wild. CISA’s inclusion of CVE-2021-43798 requires federal agencies (and signals to private orgs) to immediately remediate exposed deployments, as the vulnerability is actively used in campaigns targeting cloud, industrial, and government systems.

Remediation Guidance

Security Team Actions

Exit mobile version