Executive brief
A vulnerability in the Grafana Snowflake data source allows users with query access to move files between the Grafana server and the Snowflake host. This could allow an attacker to read sensitive local files or write malicious data to the server, potentially compromising the integrity of the monitoring platform and its connected data. This issue affects organizations using specific versions of the Snowflake plugin within their Grafana environment.
Technical details
The Grafana Snowflake datasource fails to restrict the use of Snowflake-specific GET and PUT commands within SQL queries. An attacker with low-privileged access (PR:L) to execute queries against the datasource can leverage these commands to perform unauthorized file transfers between the local filesystem of the Grafana server and the remote Snowflake environment. This vulnerability is classified with a Scope change (S:C) because it allows an attacker to impact the underlying host system beyond the datasource application itself. The affected versions range from 1.14.7 to 1.14.12. Organizations should update the Snowflake datasource plugin to a patched version to mitigate this risk.
Affected products
- Grafana Snowflake Datasource 1.14.7 - 1.14.12
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory