A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2024-8118

CVE-2024-8118: Grafana Auth Bypass Vulnerability

CVE-2024-8118 is an authorization bypass flaw in Grafana that allows users with external alert instance permissions to write alert rules. This article covers technical details, affected versions, impact, and mitigation.

Published: May 26, 2026

CVE-2024-8118 Overview

CVE-2024-8118 is a broken access control vulnerability in Grafana. The alert rule write API endpoint enforces the wrong permission check. Users granted permission to write external alert instances can also write alert rules, exceeding their intended authorization boundary.

The flaw is classified under [CWE-653: Improper Isolation or Compartmentalization]. Exploitation requires an authenticated user with elevated privileges to write external alert instances, but the consequence is unintended access to alert rule modification.

Critical Impact

Authenticated users with external alert instance write permissions can modify Grafana alert rules, bypassing the principle of least privilege and potentially disrupting monitoring and incident response workflows.

Affected Products

  • Grafana (alert rule write API endpoint)
  • Refer to the Grafana Security Advisory CVE-2024-8118 for affected version ranges
  • Self-hosted and Grafana Cloud deployments using fine-grained role-based access control

Discovery Timeline

  • 2024-09-26 - CVE-2024-8118 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2024-8118

Vulnerability Analysis

Grafana uses fine-grained role-based access control (RBAC) to gate API endpoints. Each endpoint declares the permission required to invoke it. The alert rule write API endpoint declares the permission associated with external alert instances rather than the permission for writing alert rules.

As a result, a user authorized only to write external alert instances passes the authorization check on the alert rule write endpoint. The user can then create, modify, or delete alert rules. This is an authorization scope violation rather than an authentication flaw.

The attack requires network access to the Grafana API and valid credentials with the external alert instance write permission. No user interaction is needed. The confidentiality, integrity, and availability impacts are limited because the action is constrained to alerting subsystem objects.

Root Cause

The root cause is a permission mapping error in the endpoint handler registration. The endpoint references the wrong permission constant when registering its authorization middleware. This is consistent with the [CWE-653] classification, which addresses insufficient isolation between security domains in a single application.

Attack Vector

An authenticated attacker with the external alert instance write role sends a write request to the alert rule API endpoint. The Grafana authorization layer evaluates the misconfigured permission and accepts the request. The attacker can then alter alert rule definitions, silence alerts, or introduce malicious rule expressions that suppress detections during a follow-on attack.

No verified public exploit code is available for CVE-2024-8118. The vulnerability mechanism is described in prose because no validated proof-of-concept exists. See the Grafana Security Advisory CVE-2024-8118 for vendor-confirmed technical detail.

Detection Methods for CVE-2024-8118

Indicators of Compromise

  • Unexpected PUT, POST, or DELETE requests against /api/v1/provisioning/alert-rules or /api/ruler/grafana/api/v1/rules/... originating from users that hold only external alert instance write permission.
  • Audit log entries showing alert rule create or update events attributed to accounts not assigned the alert rule writer role.
  • Sudden modification or deletion of production alert rules without a corresponding change-management ticket.

Detection Strategies

  • Compare Grafana audit logs against the documented RBAC role assignments and flag any alert rule write event performed by an identity lacking the alert rule writer role.
  • Baseline normal alert rule change frequency per user and alert on statistical deviations.
  • Enable Grafana access logging at the API layer and forward to a SIEM for correlation with identity events.

Monitoring Recommendations

  • Forward Grafana audit logs and reverse-proxy access logs to a centralized log analytics platform with retention sufficient for incident review.
  • Monitor for changes to alert rule definitions, especially expressions that broaden thresholds or disable evaluations.
  • Track authentication events for service accounts holding external alert instance permissions and alert on unusual API call patterns.

How to Mitigate CVE-2024-8118

Immediate Actions Required

  • Upgrade Grafana to the fixed version listed in the Grafana Security Advisory CVE-2024-8118.
  • Review all users and service accounts assigned the external alert instance write permission and remove the grant where it is not required.
  • Audit recent alert rule changes for unauthorized modifications and restore known-good rule definitions from version control or backups.

Patch Information

Grafana Labs has released patched Grafana versions that correct the permission mapping on the alert rule write API endpoint. The fix enforces the alert rule writer permission rather than the external alert instance writer permission. Consult the Grafana Security Advisory CVE-2024-8118 for the exact patched versions covering the OSS and Enterprise distributions.

Workarounds

  • Revoke the external alert instance write permission from any account that does not strictly require it until the patch is applied.
  • Place Grafana behind a reverse proxy that restricts write methods on /api/v1/provisioning/alert-rules and /api/ruler/... to allow-listed administrative identities.
  • Store alert rule definitions in Git and reconcile drift continuously so unauthorized changes are detected and reverted automatically.
bash
# Example: list Grafana users and their roles to identify accounts holding the
# external alert instance write permission that should be reviewed.
curl -s -u admin:$GRAFANA_ADMIN_PASSWORD \
  https://grafana.example.com/api/access-control/users/permissions/search \
  | jq '.[] | select(.permissions[]?.action == "alert.instances.external:write")'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechGrafana

  • SeverityMEDIUM

  • CVSS Score5.1

  • EPSS Probability0.10%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityLow
  • CWE References
  • CWE-653
  • Technical References
  • Grafana Security Advisory CVE-2024-8118
  • Related CVEs
  • CVE-2026-21724: Grafana OSS Auth Bypass Vulnerability

  • CVE-2021-39226: Grafana Auth Bypass Vulnerability

  • CVE-2025-3260: Grafana Dashboard Auth Bypass Vulnerability

  • CVE-2025-3454: Grafana Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English