CVE-2024-9264PoC(grafana / grafana)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-02-04); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
grafana

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-04: 1Mentions · 2026-03-11: 1Mentions · 2026-07-12: 1PoC Mentioned / Linked · 2026-03-11: 1PoC Mentioned / Linked · 2026-07-12: 1Technical Details · 2026-02-04: 1Technical Details · 2026-03-11: 1Technical Details · 2026-07-12: 102-0403-1107-12
Signal classification1 categories
PoC
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • r0otk3r@r0otk3r
    PoC

    🚨 CVE-2024-9264: Critical 9.9 CVSS Grafana Command Injection & LFI via DuckDB https://www.youtube.com/watch?v=EDt-g4qr0EA #Cybersecurity #Infosec #AppSec #RCE #CommandInjection #LFI #Grafana #DuckDB #CVE20249264 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/H22ru9bVoc

    Post summary

    The tweet announces CVE-2024-9264 as a critical Grafana command injection and LFI flaw, shares a YouTube PoC video but does not mention active attacks or patch information.

    00010108
    43 followersView on X
  • r0otk3r@r0otk3r
    PoC

    🚨CVE-2024-9264: Critical RCE in Grafana 11 via DuckDB SQL Injection #CVE20249264 #Grafana #PoC #RCE #BugBounty #CyberSecurityNews #DuckDB https://t.co/BnMnWrDPng

    Post summary

    The tweet announces CVE-2024-9264, a critical RCE in Grafana 11 via DuckDB SQL injection, and indicates a proof‑of‑concept has been shared.

    00010129
    42 followersView on X
  • strikoder@Strikoder
    PoC

    New HackTheBox walkthrough: Planning Subdomain enumeration → Grafana CVE-2024-9264 RCE → SSH port forwarding → crontab escalation to root. Full attack chain breakdown. https://youtu.be/uoweAzF5uvI #HackTheBox #OSCP #Grafana

    Post summary

    The post details a HackTheBox walkthrough demonstrating exploitation of Grafana CVE-2024-9264 via RCE, SSH forwarding, and crontab escalation, but does not provide explicit PoC code or patch information.

    00010134
    15 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana11.0.0--

Explore more