PT-2026-40793 · Grafana · Grafana Oss

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-33380

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

Fix

Related Identifiers

CVE-2026-33380

Affected Products

Grafana Oss