CVE-2019-15043: Grafana

High severity, CVSS 7.5. EPSS: 63.4% chance of exploitation in the next 30 days.

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

Affected products

  • Grafana Grafana: from 2.0.0, before 5.4.5 (fixed in 5.4.5); from 6.0.0, before 6.3.4 (fixed in 6.3.4)

Published 2019-09-03. Last modified 2026-06-17.