Description

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

INFO

Published Date :

2026-03-27T14:24:36.771Z

Last Modified :

2026-03-28T03:55:48.690Z

Source :

GRAFANA
AFFECTED PRODUCTS

The following products are affected by CVE-2026-27876 vulnerability.

Vendors Products
Grafana
  • Grafana Enterprise
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-27876.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact