S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 26, 2025

CVE-2023-3128 Scanner

CVE-2023-3128 Scanner - Account Takeover vulnerability in Grafana

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
CVECVE-2023-3128
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Grafanaby Grafana
AFFECTED< 9.5.4SAFE ✓≥ 9.5.4
Grafana Enterpriseby Grafana
AFFECTED< 9.5.4SAFE ✓≥ 9.5.4
Updated Aug 22, 2026View on NVD →
Detail

Grafana is a widely-used analytics and interactive visualization software that helps users compile data from various sources through a versatile dashboard. It is primarily used by IT professionals, data analysts, and developers in industry sectors like technology, finance, and healthcare. The platform is designed to integrate with various databases and cloud services to provide real-time insights, aiding performance monitoring and business analysis. Its open-source model allows for extensive community contribution and plugin development. Grafana supports various visualization options, enabling users to create intuitive and detailed dashboards. Its popularity is partly due to its flexibility and capability to scale with the needs of growing enterprises.

The vulnerability detected in this case pertains to account takeover, which can lead to unauthorized access to Grafana dashboards and data. This occurs when Azure AD OAuth is configured with a multi-tenant application, allowing email fields that are not unique to be exploited. The vulnerability lies in the improper validation of Azure AD accounts based on email claims. Attackers can manipulate the email field, which should be unique, to gain unauthorized access. Such a flaw can lead to significant security breaches if not addressed promptly. This issue notably affects versions from 6.7.0 to 10.0.0 in specified intervals, posing a risk of severe impact.

The technical specifics of this vulnerability involve the Grafana platform's login process, specifically when interacting with Azure AD OAuth. It emerges due to the platform's reliance on modifiable email claims rather than unique identifiers when interfacing with Azure AD's multi-tenant application configurations. During this interaction, certain email claims can be altered, compromising user accounts' security. This miscommunication between Grafana and Azure AD results in potential unauthorized access for malicious actors. Versions impacted by this poor validation can see attackers bypass authentication hurdles, compromising data integrity and user trust.

Exploitation of this vulnerability can have serious consequences, including unauthorized access and control over Grafana accounts. This might lead to data leaks, modification of dashboards, and disruption in service integrity. Attackers gaining access to sensitive information can conduct further exploitation or disseminate data leaks externally. Compromised accounts can also be used to forge and manipulate reports, leading to misleading insights within organizations. Overall, this security flaw can greatly undermine Grafana's reliability and customer trust if exploited effectively by malicious entities.

REFERENCES

Solution Advice
  • Upgrade to a patched version of Grafana that addresses this vulnerability.
  • Implement additional verification for Azure AD account claims to ensure email field uniqueness.
  • Regularly audit and monitor user access logs for unusual activity to quickly identify exploitation attempts.
  • Consider deploying multifactor authentication for an added layer of security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.