CVE-2026-27877

Public dashboards discloses all direct mode datasources

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.


We have discovered 477 live websites that are affected by CVE-2026-27877.

Run a Free Instant Scan




Affected Software

Product  Grafana
Category Analytics
Vulnerable Domains477 live websites (74% of Grafana install base)
Vulnerable Versions
  • from 9.3 through 11.6.14
  • from 12 through 12.1.10
  • from 12.2 through 12.2.8
  • from 12.3 through 12.3.6
  • from 12.4 through 12.4.2
Vulnerable Versions Count57 versions ( 65% of all versions)



Details

  • Published - Mar 27, 2026
  • Updated - Apr 9, 2026

Website Distribution by Country

Number of websites using CVE-2026-27877
United States158 websites



Germany104 websites
France51 websites
Russia24 websites
Switzerland16 websites
China12 websites
Singapore11 websites
Netherlands10 websites
Czech Republic7 websites

Website Distribution by TLD

Number of websites using CVE-2026-27877
.com154 websites
.net52 websites
.org45 websites
.de38 websites
.ru24 websites
.ch20 websites
.eu13 websites
.io11 websites
.fr9 websites
.com.br7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-27877

Top websites that are affected by CVE-2026-27877. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*******.io France**,***
********.info France***,***
*******************.com United States***,***
*******.*******.org United States*,***,***
*******.*********.org United States*,***,***
*******.***.ch Switzerland*,***,***
*******.net United States*,***,***
******.*******.com United States*,***,***
*******.io United States*,***,***
*********.com United States*,***,***
See full domain list

FAQ

A total of 477 websites have been identified as vulnerable to CVE-2026-27877, based on global website indexing conducted by WebTechSurvey.
The Grafana is affected by the CVE-2026-27877 vulnerability.
Grafana versions up to 12.4.2 are vulnerable to CVE-2026-27877.
CVE-2026-27877 is resolved in version 12.4.2 of Grafana.