Remote Code Execution Vulnerability in Snowflake Data Source by Grafana
CVE-2026-28381

9.6CRITICAL

Key Information:

Vendor

Grafana

Vendor
CVE Published:
22 June 2026

What is CVE-2026-28381?

The Snowflake datasource in Grafana has a vulnerability that permits unauthorized GET/PUT commands. This vulnerability allows any user, with access to the datasource, to execute queries that can read from and write files between the local Grafana server and the connected Snowflake host, creating a significant risk for data integrity and confidentiality.

Affected Version(s)

Snowflake Datasource 1.14.7 <= 1.14.12

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stargravy (Researcher)
.