How to audit a Grafana instance in 2026
Dashboard open with no login?
Deeper than a manual audit or a tool. At the scale AI agents attack.
The audit starts after signup. $49 for one month. Your report stays in your account.
- Version and plugins
- Anonymous access
- Sign-up
- Adjacent metrics
01 / 08·running
Public surface
Other hosts and open ports
Signals
- Version and pluginsThe Grafana release, and plugins when the API will list them.
- Anonymous accessAn org role, the home dashboard, and snapshots with no login.
- Sign-upAnyone on the internet can create an account.
- Adjacent metricsPrometheus health or config endpoints on the same host.
How the Grafana audit runs
What else is on this domain
Other hostnames on the same domain, then the ports those servers leave open, before anything Grafana-specific.
Subdomains
Staging, old admin hosts, and the other names on your domain.
Live hosts
Which of those names actually answer.
Open ports
What is listening, including the version when the server says it.
On your Grafana
Grafana version and plugins, anonymous dashboards, open sign-up, and Prometheus on the same host.
Version and plugins
The Grafana release, and plugins when the API will list them.
Anonymous access
An org role, the home dashboard, and snapshots with no login.
Sign-up
Anyone on the internet can create an account.
Adjacent metrics
Prometheus health or config endpoints on the same host.
A report you can act on
Each issue names the host, shows the evidence, and says what to fix. Anything we could not confirm stays marked that way.
Evidence
The URL or file that proved it.
CVE ids
Only when we saw the version the advisory is about.
Account
The report opens after the $49 month is paid.
Questions about a Grafana audit
What the run covers, and when the report opens in the account.
Contact usAudit Grafana from the outside.
Deeper than a manual audit or a tool. At the scale AI agents attack.