CVE-2019-19499: Grafana

Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

Affected products

  • Grafana Grafana: up to and including 6.4.3

Published 2020-08-28. Last modified 2026-06-17.