Over 46,000 Grafana instances exposed to account takeover bug
A client-side open redirect vulnerability that permits the execution of a malicious plugin and account takeover is still present in over 46,000 internet-facing Grafana instances that have not been patched.
Multiple iterations of the open-source platform used to monitor and visualize infrastructure and application metrics are affected by the vulnerability, which is recorded as CVE-2025-4123.
Bug bounty hunter Alvaro Balada found the vulnerability, which Grafana Labs fixed in security upgrades published on May 21.
According to researchers from application security firm OX Security, who call the problem "The Grafana Ghost," as of this writing, approximately one-third of all Grafana instances accessible over the public internet had not been fixed.
According to BleepingComputer, th...

