Impact
The Grafana Global Hub contains hardcoded administrator credentials (admin / admin) within its pkg/specsyncer component. These constant defaults can be leveraged by an attacker to authenticate as a Grafana administrator, granting full control over dashboards, data sources, and configuration. Unauthorized use of these credentials could compromise the confidentiality, integrity, and availability of Grafana and any managed data within the system. The hardcoded credentials are inferred from the CVE title; the official description does not detail this explicitly.
Affected Systems
The vulnerability affects the Grafana Global Hub product. No specific vendor product versions are listed, so all deployments containing the pkg/specsyncer module with the hardcoded credentials are potentially impacted.
Risk and Exploitability
The CVSS score of 9.8 places this exploit in the Critical severity range. The EPSS score is not available, but the lack of a KEV listing does not diminish the risk; hardcoded default credentials are a classic, low‑effort attack vector. The vulnerability can be exploited remotely through any exposed Grafana endpoint that allows username/password authentication, provided the attacker knows the default credentials.
OpenCVE Enrichment