Junglewise Threat Intelligence

CVE-2026-33380: Grafana arbitrary file read in SQL Expressions

CVE-2026-33380 · Severity: medium · CVSS 6.3 · Published 2026-05-13

Technologies: github.com/grafana/grafana (Go). Vendors: Grafana, Go.

Executive brief

Grafana is a popular open-source platform used for monitoring and visualizing data. A security vulnerability in its SQL Expressions feature allows a logged-in user to read sensitive files directly from the server's storage. This could lead to the exposure of configuration files, credentials, or other private system data, though it only affects systems where the specific 'sqlExpressions' feature is manually enabled.

Technical details

A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in Grafana's SQL Expressions component. The flaw allows an authenticated attacker with low privileges to perform arbitrary file reads from the underlying server filesystem. Exploitation is contingent upon the 'sqlExpressions' feature toggle being enabled. The vulnerability was addressed by implementing stricter access controls and input validation within the SQL expression handling logic. Patches are available in security-specific releases for versions 11.6, 12.2, 12.3, 12.4, and 13.0.

Affected products

  • Grafana Grafana OSS 11.6.0 to 11.6.14, 12.0.0 to 12.2.8, 12.3.0 to 12.3.6, 12.4.0 to 12.4.3, 13.0.0 to 13.0.1

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: patched
  • 2026-05-13: advisory

References

Related threats