ZeroHour

CVE-2026-33380

CVSS 3.1
6.5 medium
EPSS
<1%p28
Published
()
Modified
Description

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

Vendors
grafana
Products
grafana
Weakness
CWE-552
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.