CVE-2024-8118 is an authorization vulnerability in Grafana in which the alert rule write API endpoint enforces the wrong permission. Users who are granted permission to write external alert instances are incorrectly allowed to write alert rules as well. The flaw is caused by improper permission mapping or access-control enforcement on the alerting API, resulting in a privilege boundary failure between external alert instance management and alert rule management.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python proof-of-concept exploit (poc.py) targeting CVE-2024-8118 in Grafana. The script demonstrates that a user with Viewer privileges can create alert rules via the Grafana HTTP API, which should not be allowed. The exploit requires the attacker to know the Grafana instance URL, a valid Viewer token, the datasource UID, and the namespace. The script constructs a POST request to the /api/ruler/{datasource_uid}/api/v1/rules/{namespace} endpoint with a crafted payload to create an alert. The response is checked to determine if the exploit was successful (i.e., if the Viewer user was able to create an alert). The repository is a straightforward PoC, containing only the exploit script, and does not include any framework or auxiliary files.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.