PT-2026-28369 · Grafana · Grafana

Published

2026-03-25

·

Updated

2026-04-30

·

CVE-2026-27876

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Grafana versions 11.6.0 through 11.6.14, 12.0.0 through 12.1.10, 12.2.0 through 12.2.8, 12.3.0 through 12.3.6, and 12.4.0 through 12.4.2.
Description: A chained attack involving SQL Expressions and a Grafana Enterprise plugin can lead to remote arbitrary code execution (RCE). The issue is enabled by the sqlExpressions feature in Grafana (OSS). Exploitation involves injecting malicious SQL expressions that, when processed by a vulnerable Grafana Enterprise plugin, can trigger code evaluation and lead to RCE. Approximately 83,000 instances are estimated to be exposed globally. The vulnerability allows for full system compromise, potentially including authentication bypass and SSH access to host servers.
Recommendations: Upgrade to Grafana version 11.6.14 or later. Upgrade to Grafana version 12.1.10 or later. Upgrade to Grafana version 12.2.8 or later. Upgrade to Grafana version 12.3.6 or later. Upgrade to Grafana version 12.4.2 or later. Disable the sqlExpressions feature toggle if an immediate upgrade is not possible.

Exploit

Fix

RCE

DoS

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-04159
BIT-GRAFANA-2026-27876
CVE-2026-27876
OPENSUSE-SU-2026:10601-1
SUSE-SU-2026:1524-1

Affected Products

Grafana