S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-26148 Scanner

CVE-2022-26148 scanner - Credential Disclosure vulnerability in Grafana

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-26148
9.8
CVSS

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Grafana is an open source data visualization platform that allows users to query, visualize, and alert on their metrics data. It is commonly used by organizations to monitor system performance, application behavior, and user engagement. With its versatile dashboards, users can create custom visualizations that display data from various sources such as databases, APIs, and other monitoring tools. The platform provides real-time updates and alerts, making it a valuable tool for system administrators and DevOps teams.

One of the vulnerabilities that were discovered in Grafana is CVE-2022-26148. This vulnerability was detected in versions up to 7.3.4, commonly used when integrating with Zabbix. The issue lies in the html source code of the api_jsonrpc.php page, which contains the Zabbix password in plain text. This exposes the Zabbix account password and URL address to potential attackers.

Exploiting this vulnerability can lead to severe consequences. Attackers can gain unauthorized access to sensitive data, alter system configurations, and execute malicious code. This can result in system downtime, loss of data, and financial losses for the affected organizations. Therefore, it is crucial for users to take precautions to protect their assets against such threats.

With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability assessments, customized reports, and real-time alerts, enabling users to identify and mitigate potential threats proactively. By using such advanced tools, organizations can ensure the security and integrity of their valuable data and systems.

 

REFERENCES

Solution Advice

To safeguard against this vulnerability, users should implement the following precautions:

  • Upgrade to the latest version of Grafana.
  • Use strong and unique passwords for all user accounts and API keys.
  • Restrict access to sensitive data and system settings.
  • Regularly monitor system logs and activity.
  • Use a web application firewall to protect against malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-26148 scanner - Credential Disclosure vulnerability in Grafana S4E