SQL Injection Vulnerability in Grafana by Grafana Labs
CVE-2026-33380
6.3MEDIUM
What is CVE-2026-33380?
An SQL injection vulnerability exists in Grafana's SQL Expressions feature. This flaw enables authenticated attackers to read arbitrary files from the server's filesystem, particularly in instances where the sqlExpressions feature toggle is enabled. This could lead to unauthorized access to sensitive data, highlighting the importance of disabling this feature when not in use and applying necessary security measures.
Affected Version(s)
Grafana OSS OnPrem 11.6.0 <= 11.6.14
Grafana OSS OnPrem 11.6.14 < 11.6.14+security-04
Grafana OSS OnPrem 12.0.0 <= 12.2.8