SQL to SSH: Critical 9.1 CVSS RCE in Grafana Turns Monitoring into a Remote Hijack
ID: e7971b18-deec-566b-b0f4-129e2339960c
STIX ID: report--e7971b18-deec-566b-b0f4-129e2339960c
Feed Name: securityonline.info
**Grafana security advisory:** Two significant vulnerabilities were disclosed — **CVE-2026-27876** (RCE, CVSS 9.1) in the sqlExpressions feature that can permit arbitrary file writes and enable full SSH access when exploited (requiring only Viewer permissions plus certain feature/config conditions), and **CVE-2026-27880** (DoS, CVSS 7.5) in unauthenticated OpenFeature endpoints that accept unbounded input and can exhaust system memory. Grafana has released 12.4.2 and patches for older supported branches; administrators are urged to upgrade immediately or apply mitigations such as disabling sqlExpressions, updating/disabling Sqlyze, disabling AWS data sources, using proxies to limit payload size, and deploying high-availability/restart mechanisms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
