• Sign in
  • Register

Lost your password?

A password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.

Close
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
Cyber Threat

46,000+ Grafana Servers at Risk: “Ghost” Bug Enables Complete Account Takeover

ClickControl

Author

June 16, 2025

Published

46,000+ Grafana Servers at Risk:

# Critical Grafana Vulnerability Leaves 46,000 Systems Exposed to Account Takeover

A serious security flaw in Grafana monitoring platforms has left over 46,000 internet-facing systems vulnerable to account takeover attacks, despite patches being available for months.

## The Vulnerability Details

The security issue, designated CVE-2025-4123, affects multiple versions of Grafana, a popular open-source platform used for monitoring and visualizing infrastructure metrics. Bug bounty hunter Alvaro Balada discovered the vulnerability, which Grafana Labs patched on May 21. However, security researchers at OX Security found that more than one-third of publicly accessible Grafana instances remain unpatched.

## Scale of the Problem

OX Security’s analysis revealed alarming exposure statistics:
– **128,864 total Grafana instances** found online
– **46,506 systems still vulnerable** (approximately 36%)
– All vulnerable systems remain at risk of exploitation

The researchers dubbed this widespread exposure “The Grafana Ghost” due to its persistent presence across the internet.

## How the Attack Works

The vulnerability combines client-side path traversal with open redirect mechanics, allowing attackers to:

1. **Trick users** into clicking malicious URLs
2. **Load harmful plugins** from attacker-controlled servers
3. **Execute arbitrary JavaScript** in victims’ browsers
4. **Hijack user sessions** and change account credentials

The exploit is particularly dangerous because it:
– Requires no elevated privileges
– Works even with anonymous access enabled
– Can bypass browser security through Grafana’s JavaScript routing
– Enables account takeover via password reset manipulation

## Additional Risks

When the Grafana Image Renderer plugin is installed, attackers can also perform server-side request forgery (SSRF) attacks to access internal network resources.

## Exploitation Requirements

While the attack has some limitations, they don’t significantly reduce the threat:
– User must click a malicious link
– Victim needs an active session
– Plugin feature must be enabled (default setting)

The large number of exposed systems and lack of authentication requirements create a substantial attack surface.

## Immediate Action Required

Grafana administrators should immediately upgrade to these secure versions:
– 10.4.18+security-01
– 11.2.9+security-01
– 11.3.6+security-01
– 11.4.4+security-01
– 11.5.4+security-01
– 11.6.1+security-01
– 12.0.0+security-01

## Bottom Line

With nearly 50,000 systems remaining vulnerable months after patches became available, this represents a significant cybersecurity risk. Organizations using Grafana should prioritize immediate updates to prevent potential account takeovers and data breaches.

Keywords: Grafana vulnerability, CVE-2025-4123, account takeover, Grafana security patch, monitoring platform exploit, cybersecurity risk

Share This Article
Tags: account takeover CVE-2025-4123 cybersecurity risk Grafana security patch Grafana vulnerability monitoring platform exploit
Previous Article WestJet Hit by Cyberattack That
Next Article OpenAI Supercharges ChatGPT Search to
Curve Line
logo_white

601 Notre Dame E.
Montreal, Quebec, H2Y 0C2

Quick Links
  • Cybersecurity News
  • Video Guides
  • Shop
Company
  • Home
  • About us
  • Contact
  • Careers
  • Privacy Policy
Get In Touch

Montreal: +1-438-600-2288
Miami: +1-786-442-1805
Toll-Free: 1-877-654-9901

Linkedin Instagram Youtube

(C) Copyright 2023-2025 ClickControl IT MSP & Cybersecurity, All Rights Reserved.