According to SlowMist, the open-source data visualization platform Grafana issued a serious security alert. It has account takeover and authentication bypass vulnerabilities (CVE-2023-3128). At present, the PoC is public on the Internet, and there have been attack cases. Grafana is a cross-platform, open source data visualization web application platform. After the user configures the connected data source, Grafana can display data charts and alerts in the web browser. Grafana authenticates the Azure Active Directory account based on the email request. On Azure AD, the email field of a profile is not unique across Azure AD tenants. This could allow Grafana account takeover and authentication bypass when Azure AD OAuth is configured with multi-tenant Azure AD OAuth applications. Of these, Grafana >= 6.7.0 is affected. A large number of platforms in the cryptocurrency industry use this solution to monitor server performance. Please be aware of risks and upgrade Grafana to the latest version.