• News/
  • https://www.bleepingcomputer.com/news/security/over-46-000-grafana-instances-exposed-to-account-takeover-bug/

Over 46,000 Grafana instances exposed to account takeover bug

BleepingComputer
·
Bill Toulas
·
Published Jun 15, 2025
·
Updated

More than 46,000 internet-facing Grafana instances remain unpatched and exposed to a client-side open redirect vulnerability that allows executing a malicious plugin and account takeover. The flaw is tracked as CVE-2025-4123 and impacts multiple versions of the open-source platform used for monitoring and visualizing infrastructure and application metrics. The vulnerability was discovered by bug bounty hunter Alvaro Balada and was addressed in security updates that Grafana Labs released on May 21. However, as of writing this, more than a third of all Grafana instances reachable over the public internet have not been patched, according to researchers at aplication security company OX Security, who refer to the bug as ‘The Grafana Ghost’. The analysts told BleepingComputer that their work focused on demonstrating the ability to weaponize Balada's finding. After identifying versions vulnerable to the attack, they assesed the exposure by correlating the data with the platform's distribution across the ecosystem. They found 128,864 instances exposed online, with 46,506 still running vulnerable versions that can still be exploited. This corresponds to a percentage of about 36%. OX Security’s in-depth analysis of CVE-2025-4123 uncovered that, through a series of exploitation steps combining client-side path traversal with open redirect mechanics, attackers can lure victims into clicking URLs that lead to loading a malicious Grafana plugin from a site controlled by the threat actor....

Read full article

Affected Software

1 affected component
Grafana Labs Grafana
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in Grafana instances that exposes them to account takeover threats.

2

What security implications are discussed in the article?

The article highlights the risks of unpatched Grafana instances being susceptible to a client-side open redirect vulnerability.

3

How many Grafana instances are affected by this vulnerability?

Over 46,000 internet-facing Grafana instances are reported to be exposed to the vulnerability.

4

What is the specific vulnerability tracked in the article?

The vulnerability is tracked as CVE-2025-4123.

5

What actions should users of Grafana take in response to the vulnerability?

Users of Grafana should patch their instances promptly to prevent potential account takeover.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203