logo

SQL to SSH: Critical 9.1 CVSS RCE in Grafana Turns Monitoring into a Remote Hijack

ID: e7971b18-deec-566b-b0f4-129e2339960c

STIX ID: report--e7971b18-deec-566b-b0f4-129e2339960c

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-29

Date Updated: 2026-04-23

Author: Ddos

...
...

**Grafana security advisory:** Two significant vulnerabilities were disclosed — **CVE-2026-27876** (RCE, CVSS 9.1) in the sqlExpressions feature that can permit arbitrary file writes and enable full SSH access when exploited (requiring only Viewer permissions plus certain feature/config conditions), and **CVE-2026-27880** (DoS, CVSS 7.5) in unauthenticated OpenFeature endpoints that accept unbounded input and can exhaust system memory. Grafana has released 12.4.2 and patches for older supported branches; administrators are urged to upgrade immediately or apply mitigations such as disabling sqlExpressions, updating/disabling Sqlyze, disabling AWS data sources, using proxies to limit payload size, and deploying high-availability/restart mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.