Junglewise Threat Intelligence

CVE-2026-27876: Grafana remote code execution via SQL Expressions and Enterprise plugin

CVE-2026-27876 · Severity: critical · CVSS 9.1 · Published 2026-03-27

Vendors: Grafana Labs.

Executive brief

Grafana is a popular data visualization and monitoring platform used to track infrastructure health and business metrics. A security vulnerability has been identified where a combination of specific SQL features and an Enterprise plugin can allow an attacker to take full control of the server. This could lead to the theft of sensitive data, disruption of monitoring services, or further attacks on the internal network.

Technical details

This vulnerability is a chained attack involving SQL Expressions (CWE-89) and a Grafana Enterprise plugin, resulting in remote code execution (CWE-94). The vulnerability is only exploitable if the 'sqlExpressions' feature toggle is enabled. An attacker with high privileges (PR:H) can leverage this chain to execute arbitrary commands on the host system with the permissions of the Grafana process. The issue affects multiple versions across the 11.x and 12.x branches, but has been patched in versions 11.6.14, 12.1.10, 12.2.8, 12.3.6, and 12.4.2. Version 13.0.0 and later are not affected.

Affected products

  • Grafana Labs Grafana 11.6.0 to 11.6.13, 12.0.0 to 12.1.9, 12.2.0 to 12.2.7, 12.3.0 to 12.3.5, 12.4.0 to 12.4.1

Timeline

  • 2026-03-27: disclosed
  • 2026-03-27: advisory

References