Remote Code Execution Vulnerability in Snowflake Data Source by Grafana
CVE-2026-28381
9.6CRITICAL
What is CVE-2026-28381?
The Snowflake datasource in Grafana has a vulnerability that permits unauthorized GET/PUT commands. This vulnerability allows any user, with access to the datasource, to execute queries that can read from and write files between the local Grafana server and the connected Snowflake host, creating a significant risk for data integrity and confidentiality.
Affected Version(s)
Snowflake Datasource 1.14.7 <= 1.14.12