logo

Critical Grafana Flaws Allow Attackers to Achieve Remote Code Execution

ID: a7960bfd-8b62-58f2-ae25-15d25b13733a

STIX ID: report--a7960bfd-8b62-58f2-ae25-15d25b13733a

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Divya

...
...

Grafana released critical patches for two vulnerabilities: CVE-2026-27876 (CVSS 9.1) is an arbitrary file write in the sqlExpressions feature that can be chained to achieve remote code execution and direct SSH access (affects Grafana >= 11.6.0); CVE-2026-27880 (CVSS 7.5) is an unauthenticated OpenFeature endpoint input validation issue that can be abused to exhaust memory and cause a DoS (affects Grafana >= 12.1.0). Administrators are urged to upgrade to patched versions (12.4.2, 12.3.6, 12.2.8, 12.1.10, or 11.6.14) or apply mitigations such as disabling sqlExpressions, disabling AWS data sources, removing/updating the Sqlyze driver, and limiting inbound payload sizes behind a proxy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.