Description
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
INFO
Published Date :
2026-03-27T14:24:36.771Z
Last Modified :
2026-03-28T03:55:48.690Z
Source :
GRAFANA
AFFECTED PRODUCTS
The following products are affected by CVE-2026-27876 vulnerability.
| Vendors | Products |
|---|---|
| Grafana |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-27876.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact