The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added the Grafana path traversal vulnerability, CVE-2021-43798, to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the ongoing risk this flaw poses to organizations. CVE-2021-43798 is a directory traversal vulnerability affecting Grafana versions 8.0.0-beta1 through 8.3.0, which allows unauthenticated attackers to access files outside of intended directories by manipulating HTTP requests to the /public/plugins/<plugin-id>/ path. This vulnerability enables threat actors to read sensitive files such as /etc/passwd, configuration files, OAuth tokens, and internal databases containing user and data source information. Since its disclosure in December 2021, the vulnerability has been actively exploited in the wild, with persistent scanning and attacks targeting internet-facing Grafana servers. The risk is particularly acute for critical infrastructure, cloud environments, and enterprise deployments where Grafana is widely used for observability and monitoring. Publicly available exploit code has facilitated ongoing exploitation, making unpatched systems especially vulnerable. CISA’s decision to add this vulnerability to the KEV catalog is based on confirmed evidence of active exploitation, underscoring the significant risk it poses to the federal enterprise and beyond. Under Binding Operational Directive (BOD) 22-01, all Federal Civilian Executive Branch (FCEB) agencies are required to remediate this vulnerability by a specified due date to protect their networks from active threats. CISA also strongly encourages all organizations, not just federal agencies, to prioritize remediation of KEV catalog vulnerabilities as part of their vulnerability management programs. The agency’s alert emphasizes that path traversal vulnerabilities like CVE-2021-43798 are frequent attack vectors for malicious cyber actors. Organizations are advised to immediately upgrade affected Grafana instances to patched versions to mitigate the risk of compromise. The inclusion of this vulnerability in the KEV catalog serves as a warning to both public and private sector entities about the ongoing exploitation and the need for urgent action. CISA will continue to monitor and update the KEV catalog as new evidence of exploitation emerges. The agency provides additional resources and fact sheets to help organizations understand the requirements and best practices for addressing known exploited vulnerabilities. The move reflects CISA’s broader strategy to reduce the significant risk posed by actively exploited vulnerabilities across the federal enterprise and the wider cybersecurity ecosystem. Organizations that fail to remediate this vulnerability remain at heightened risk of data breaches and system compromise. The continued exploitation of CVE-2021-43798 demonstrates the importance of timely patching and proactive vulnerability management. CISA’s alert and catalog update are intended to drive immediate action and raise awareness of the persistent threat posed by this Grafana vulnerability.

See which actors are running it and whether you're in range.
1 event from the most recent confirmed update back to the earliest known activity.
CISA added Grafana path traversal vulnerability CVE-2021-43798 to its Known Exploited Vulnerabilities catalog, indicating evidence of active exploitation. The addition was publicly announced in CISA's October 9, 2025 alert and subsequently reported by other outlets.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.