CVE-2026-27876 details a critical Remote Code Execution (RCE) vulnerability in Grafana, stemming from a chained attack involving SQL Expressions and a Grafana Enterprise plugin. This vulnerability affects specific Grafana versions (e.g., 11.6.x, 12.x) when the `sqlExpressions` feature toggle is enabled. Rated 9.1 CRITICAL (CVSS:3.1), it allows a highly privileged attacker to achieve RCE with low attack complexity, posing a severe risk to system confidentiality, integrity, and availability. Although not yet listed on CISA's KEV catalog and lacking public exploit code, the vulnerability is on the Hot List and has generated significant community discussion, indicating active awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.6.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* | ||
>= 11.6.14, < 12.0.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* | ||
>= 12.1.10, < 12.2.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* | ||
>= 12.2.8, < 12.3.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* | ||
>= 12.3.6, < 12.4.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.