When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
We have discovered 477 live websites that are affected by CVE-2026-27877.
| Product | |
| Category | Analytics |
| Vulnerable Domains | 477 live websites (74% of Grafana install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 57 versions ( 65% of all versions) |
| 158 websites | |
| 104 websites | |
| 51 websites | |
| 24 websites | |
| 16 websites | |
| 12 websites | |
| 11 websites | |
| 10 websites | |
| 7 websites |
| .com | 154 websites |
| .net | 52 websites |
| .org | 45 websites |
| .de | 38 websites |
| .ru | 24 websites |
| .ch | 20 websites |
| .eu | 13 websites |
| .io | 11 websites |
| .fr | 9 websites |
| .com.br | 7 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.*******.io | **,*** | ||
| ********.info | ***,*** | ||
| *******************.com | ***,*** | ||
| *******.*******.org | *,***,*** | ||
| *******.*********.org | *,***,*** | ||
| *******.***.ch | *,***,*** | ||
| *******.net | *,***,*** | ||
| ******.*******.com | *,***,*** | ||
| *******.io | *,***,*** | ||
| *********.com | *,***,*** |
FAQ