Critical Grafana Flaws Allow Attackers to Achieve Remote Code Execution
ID: a7960bfd-8b62-58f2-ae25-15d25b13733a
STIX ID: report--a7960bfd-8b62-58f2-ae25-15d25b13733a
Feed Name: GBHackers
Grafana released critical patches for two vulnerabilities: CVE-2026-27876 (CVSS 9.1) is an arbitrary file write in the sqlExpressions feature that can be chained to achieve remote code execution and direct SSH access (affects Grafana >= 11.6.0); CVE-2026-27880 (CVSS 7.5) is an unauthenticated OpenFeature endpoint input validation issue that can be abused to exhaust memory and cause a DoS (affects Grafana >= 12.1.0). Administrators are urged to upgrade to patched versions (12.4.2, 12.3.6, 12.2.8, 12.1.10, or 11.6.14) or apply mitigations such as disabling sqlExpressions, disabling AWS data sources, removing/updating the Sqlyze driver, and limiting inbound payload sizes behind a proxy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
