Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27876

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path.

Only instances with the sqlExpressions feature toggle enabled are vulnerable.

EPSS

Процентиль: 23%
0.00079
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.1
redhat
4 дня назад

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 9.1
debian
4 дня назад

A chained attack via SQL Expressions and a Grafana Enterprise plugin c ...

CVSS3: 9.1
github
4 дня назад

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

EPSS

Процентиль: 23%
0.00079
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94