Anonymous access in a monitoring tool sounds harmless. It is read-only, after all — a viewer role, for dashboards on a wall.
The opening
But read-only in this product includes reading the datasource configuration, which holds the database connection. And it includes using that datasource to run queries. The result is a dashboard that quietly becomes an unauthenticated database proxy, open to the entire internet.
Every request below was made with no cookies, no tokens and no credentials of any kind.
What read-only actually meant
The instance was three years old, running an OSS build with five known CVEs, and configured to auto-assign the viewer role to anonymous visitors. Here is what that viewer could reach.
- Anonymous request — no credentials.
- Version and health fingerprinted.
- Datasource configuration returned the connection.
- The query proxy accepted raw SQL.
- The statement was parsed, forwarded and echoed verbatim.
- The production database was offline at test time.
The datasource record gave up the whole connection: engine, hostname, region derived from the DNS name, database name, username, and the fact that a password sat stored server-side. The connection string to the company’s production database, served to an anonymous request.
The queries returned no rows for exactly one reason: the database hostname was temporarily unresolvable. Not an authentication failure. Not an authorisation check. The database happened to be offline.
A DNS record is not a security control.
The rest of the anonymous surface
Query execution was the headline. It was not the only thing the viewer role handed over.
Internal URL, no single sign-on configured, and HTML sanitisation explicitly disabled — the precondition for stored cross-site scripting.
Over three thousand lines of Prometheus data describing how the system runs and what it talks to.
Full JSON, including the SQL embedded in every panel — effectively a schema map.
Forty-nine plugins enumerated, each one a version to check against public advisories.
Not read-only at all. Data-integrity tampering, and a delivery path for the stored XSS above.
The second host
The same engagement found a build server on a neighbouring hostname running a release that reached end of life in January 2026. No future security patch will ever be issued for it.
It is vulnerable to an arbitrary-file-write flaw rated 9.9 — symlink traversal in archive handling. A user with permission to configure a job can write a startup script into the initialisation directory or drop a rogue plugin, which is full controller compromise and, from there, poisoned build artefacts and a readable credential store. Supporting issues included version-disclosure headers, a publicly downloadable command-line client, DNS-rebinding command execution, and stored XSS.
The chains
Twenty-seven findings across two hosts. Individually they read like a patch backlog. Assembled, they are three concrete paths.
Anonymous API → extract connection → arbitrary SQL via proxy → enumerate and exfiltrate → OS command execution if shell execution is enabled.
Archive symlink traversal → write startup script → controller code execution → poison artefacts, read credential store.
Sanitisation disabled + anonymous annotation write → stored payload → steal admin session → modify datasource → extract stored password.
The database must be online. The anonymous API, exposed connection and arbitrary-SQL proxy were already reachable.
Five additional findings were rated low.
Root cause and remedy
One setting exposed seven of the findings at once. Anonymous access was never designed to face the public internet; the viewer role assumes an audience that already got past your front door.
Behind it, the same pattern as every other case study we publish: internet-facing infrastructure years out of date, one component already past end of life, and credentials leaking through the tooling that was supposed to be watching everything else. Monitoring and build systems sit close to production data and the release pipeline, and they are routinely the least maintained things an organisation runs.
Read-only is not safe when read-only includes your datasource config and a query proxy. Check what the role can reach, not what it is called.
A DNS record is not a security control. The database was protected by being offline. Bring it back and the exposure is immediate.
End-of-life software is a standing critical. Once patches stop, every future CVE is permanent.
The highest-leverage fix is often one line. Disabling anonymous access remediates seven of these findings in a single change.