# Grafana 9.2.4 (grafana.netbank.ph) — CVE surface map (2026-08-17, offline research)

Fingerprint: `/api/health` → version 9.2.4, commit 64017e8ca6 (released 2022-11-09).
Boot data (login page): `oauth:{}` (NO OAuth providers configured),
`authProxyEnabled:false`, `samlEnabled:false`, `disableLoginForm:false`,
`disableUserSignUp:true`, `verifyEmailEnabled:false`, `rbacEnabled:true`,
`autoAssignOrg:true`, `viewersCanEdit:false`, `rendererAvailable:false`.
=> Auth = local basic/form only. Multi-tenant Azure AD / OAuth paths NOT in play.

## CVE timeline vs 9.2.4 (patched-after markers from grafana releases + NVD)

| CVE | Sev | Type | Affected | Needs | Applicable? |
|-----|-----|------|----------|-------|-------------|
| CVE-2023-3128 | 9.4 Crit | Azure AD multi-tenant email-claim account takeover | 9.2.0–9.2.19 (fixed 9.2.20) | Azure AD OAuth configured | **NO** — oauth:{} empty |
| CVE-2023-4822 | 6.7 Med | Org Admin cross-org privesc | 8.0.0–9.4.16 (9.2.4 inside) | valid Org Admin cred | blocked (no cred) |
| CVE-2023-2183 | Med | Viewer-role alert test via API | 9.0.0–9.2.19 (9.2.4 inside) | valid Viewer cred | blocked |
| CVE-2024-1442 | 6 Med | DS-create with uid=* → full DS read/write | 8.5.0–9.5.7 (9.2.4 inside) | valid DS-create priv cred | blocked |
| CVE-2023-6152 | Med | email change w/o re-verification | grafana <10.3.0 | valid cred | blocked; low value |
| CVE-2023-2801 | Med | public-dashboard mixed-query DoS | 9.4.0–9.5.3 | — | NOT in 9.2.4 |
| CVE-2021-43798 | 7.5 High | path traversal unauth file read | 8.0.0–8.3.1 | — | NOT in 9.2.4 |
| CVE-2022-39229 | Med | email-as-username block | <9.2 (fixed in 9.2) | — | patched |

## Verdict

**No unauthenticated RCE / auth-bypass path exists against stock Grafana 9.2.4.**
The single critical unauth vector of the 9.2 line (CVE-2023-3128) requires Azure AD
OAuth — target boot config shows zero OAuth providers. All remaining applicable
CVEs are authenticated (need at least Viewer/OrgAdmin/DS-create creds — exactly
what we lost to rotation).

Residual surfaces (NOT pursued, listed for completeness):
- Plugin-level vulns: boot data shows stock panels only, no exotic plugins
  observed in page bundle manifest. Unknown plugins would need auth anyway.
- DoS-class (public dashboards): public dashboards feature off by default in
  9.2.4; probing them = active noise, out of read-only scope.
- Brute-force / pw-spray vs /login: out of scope (RoE: no brute-force without
  explicit approval; also ASP-regulated bank — lockout/alert risk high).

## Sources
- grafana.com/security/security-advisories/cve-2023-4822/ (extracted 2026-08-17)
- grafana.com/blog/grafana-security-release-for-cve-2023-3128/
- NVD API 2.0 per-CVE CPE ranges (CVE-2023-6152, -2024-1442, -2023-4822, -2023-3128, -2023-2183, -2023-2801)
- github.com/grafana/grafana releases v9.2.5..v9.2.20 changelog scan (CVE-2023-3128 fixed in v9.2.20 only)
- Target boot config: /login page JSON blob (extracted 2026-08-17, 1 GET)
