No login required: a Grafana that hands out database credentials

A public dashboard with anonymous access enabled exposed a production database connection and accepted arbitrary unauthenticated SQL through its own datasource proxy. The only thing standing between a stranger and the database was a DNS record.

Cutaway clay model of connected infrastructure components
A gauge panel with a pipe running straight out of it, and no valve anywhere along the line.

Anonymous access in a monitoring tool sounds harmless. It is read-only, after all — a viewer role, for dashboards on a wall.

2Hosts
27Findings · 4 critical
NoneCredentials used

The opening

But read-only in this product includes reading the datasource configuration, which holds the database connection. And it includes using that datasource to run queries. The result is a dashboard that quietly becomes an unauthenticated database proxy, open to the entire internet.

Every request below was made with no cookies, no tokens and no credentials of any kind.

What read-only actually meant

The instance was three years old, running an OSS build with five known CVEs, and configured to auto-assign the viewer role to anonymous visitors. Here is what that viewer could reach.

Unauthenticated, end to end6 hops
  1. Anonymous request — no credentials.
  2. Version and health fingerprinted.
  3. Datasource configuration returned the connection.
  4. The query proxy accepted raw SQL.
  5. The statement was parsed, forwarded and echoed verbatim.
  6. The production database was offline at test time.
Fig. 1 — the last hop failed to resolve. Nothing along the way refused the request.
Evidence — unauthenticated requestsNo credentials sent
GET /api/health → 200 · version 10.0.1, database ok GET /api/datasources → 200 · mssql · host [redacted].rds.amazonaws.com · user [redacted] POST /api/ds/query · {"rawSql":"SELECT @@version"} → 200 · executedQueryString echoed back verbatim — the proxy parsed and forwarded it
Fig. 2 — three distinct queries were forwarded, including one selecting rows from a live data table.

The datasource record gave up the whole connection: engine, hostname, region derived from the DNS name, database name, username, and the fact that a password sat stored server-side. The connection string to the company’s production database, served to an anonymous request.

The queries returned no rows for exactly one reason: the database hostname was temporarily unresolvable. Not an authentication failure. Not an authorisation check. The database happened to be offline.

A DNS record is not a security control.

The rest of the anonymous surface

Query execution was the headline. It was not the only thing the viewer role handed over.

Frontend settings

Internal URL, no single sign-on configured, and HTML sanitisation explicitly disabled — the precondition for stored cross-site scripting.

Operational metrics

Over three thousand lines of Prometheus data describing how the system runs and what it talks to.

Dashboard definitions

Full JSON, including the SQL embedded in every panel — effectively a schema map.

Plugin inventory

Forty-nine plugins enumerated, each one a version to check against public advisories.

Annotation write and delete

Not read-only at all. Data-integrity tampering, and a delivery path for the stored XSS above.

The second host

The same engagement found a build server on a neighbouring hostname running a release that reached end of life in January 2026. No future security patch will ever be issued for it.

It is vulnerable to an arbitrary-file-write flaw rated 9.9 — symlink traversal in archive handling. A user with permission to configure a job can write a startup script into the initialisation directory or drop a rogue plugin, which is full controller compromise and, from there, poisoned build artefacts and a readable credential store. Supporting issues included version-disclosure headers, a publicly downloadable command-line client, DNS-rebinding command execution, and stored XSS.

Cutaway clay model illustrating a temporary gap between connected systems
Fig. 3 — the gap in the line was temporary. Everything either side of it was permanent.

The chains

Twenty-seven findings across two hosts. Individually they read like a patch backlog. Assembled, they are three concrete paths.

Monitoring to full database compromise

Anonymous API → extract connection → arbitrary SQL via proxy → enumerate and exfiltrate → OS command execution if shell execution is enabled.

Critical
Build server to supply-chain compromise

Archive symlink traversal → write startup script → controller code execution → poison artefacts, read credential store.

Critical
Stored XSS to admin takeover

Sanitisation disabled + anonymous annotation write → stored payload → steal admin session → modify datasource → extract stored password.

High
Monitoring to database compromiseOne prerequisite

The database must be online. The anonymous API, exposed connection and arbitrary-SQL proxy were already reachable.

Fig. 4 — the first chain has one prerequisite: the database being online.
Findings by severity27 total, two hosts
4Critical
8High
10Medium

Five additional findings were rated low.

Fig. 5 — a distribution this shape is a systemic gap, not an isolated slip.

Root cause and remedy

One setting exposed seven of the findings at once. Anonymous access was never designed to face the public internet; the viewer role assumes an audience that already got past your front door.

Behind it, the same pattern as every other case study we publish: internet-facing infrastructure years out of date, one component already past end of life, and credentials leaking through the tooling that was supposed to be watching everything else. Monitoring and build systems sit close to production data and the release pipeline, and they are routinely the least maintained things an organisation runs.

Read-only is not safe when read-only includes your datasource config and a query proxy. Check what the role can reach, not what it is called.

A DNS record is not a security control. The database was protected by being offline. Bring it back and the exposure is immediate.

End-of-life software is a standing critical. Once patches stop, every future CVE is permanent.

The highest-leverage fix is often one line. Disabling anonymous access remediates seven of these findings in a single change.

Everything here was reachable without logging in.

Our agents probe what you expose the way a stranger would, then an operator assembles it into chains worth acting on.

Get a POC