CVE-2018-15727: Grafana

Critical severity, CVSS 9.8. EPSS: 64.3% chance of exploitation in the next 30 days.

Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.

Affected products

  • Grafana Grafana: from 2.0.0, up to and including 2.1.2; from 3.0.0, up to and including 3.1.1; from 4.0.0, before 4.6.4 (fixed in 4.6.4); from 5.0.0, before 5.2.3 (fixed in 5.2.3)
  • Red Hat Ceph Storage: version 3.0 only

Published 2018-08-29. Last modified 2026-06-17.