CVE-2026-27876Disclosure(grafana / grafana)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch grafana grafana systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. Only instances in the following version ranges are affected: - 11.6.0 (inclusive) to 11.6.14 (exclusive): 11.6.14 has the fix. 11.5 and below are not affected. - 12.0.0 (inclusive) to 12.1.10 (exclusive): 12.1.10 has the fix. 12.0 did not receive an update, as it is end-of-life. - 12.2.0 (inclusive) to 12.2.8 (exclusive): 12.2.8 has the fix. - 12.3.0 (inclusive) to 12.3.6 (exclusive): 12.3.6 has the fix. - 12.4.0 (inclusive) to 12.4.2 (exclusive): 12.4.2 has the fix. 13.0.0 and above also have the fix: no v13 release is affected.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 27 mentions across 12 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 20 signals
  • Disclosure: 14 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 8 mentions (2026-03-30); latest day: 1
  • 27 total mentions across 12 days

Affected systems

Vendors
Products
grafana

Deep dive

Activity timeline27 mentions / 12d
02468Mentions · 2026-03-26: 1Mentions · 2026-03-27: 5Mentions · 2026-03-28: 3Mentions · 2026-03-29: 3Mentions · 2026-03-30: 8Mentions · 2026-03-31: 1Mentions · 2026-04-03: 1Mentions · 2026-04-07: 1Mentions · 2026-04-08: 1Mentions · 2026-04-10: 1Mentions · 2026-04-30: 1Mentions · 2026-05-28: 1PoC Mentioned / Linked · 2026-03-30: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 4Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-03-30: 5Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-28: 2Technical Details · 2026-03-29: 3Technical Details · 2026-03-30: 8Technical Details · 2026-04-03: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-30: 103-2603-2703-2803-2903-3003-3104-0304-0704-0804-1004-3005-28
Signal classification3 categories
Disclosure
1451.9%
Patch
1140.7%
General
27.4%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-261
Patch1
2026-03-275
Disclosure2Patch3
2026-03-283
Disclosure2Patch1
2026-03-293
Disclosure2Patch1
2026-03-308
Disclosure4Patch4
2026-03-311
Disclosure1
2026-04-031
Disclosure1
2026-04-071
Disclosure1
2026-04-081
General1
2026-04-101
General1
2026-04-301
Patch1
2026-05-281
Disclosure1
Full discourse20 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-27876: RCE on Grafana via sqlExpressions Critical RCE via SQL Expressions + Enterprise Plugin Chain! An attacker exploits the enabled sqlExpressions feature toggle in Grafana OSS to inject malicious SQL expressions that, when processed by a vulnerable Grafana Enterprise plugin (e.g., for data transformation or dashboard scripting), triggers deserialization or code evaluation leading to remote arbitrary code execution. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-27876 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-27876" Search Dork: app="Grafana" Exposure: 83k+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJHcmFmYW5hIg==&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260330 #Grafana #RCE #SQLInjection #ChainedVuln #EnterpriseRisk #DarkEye

    Post summary

    The tweet announces the discovery of CVE‑2026‑27876, a critical RCE in Grafana caused by exploiting sqlExpressions together with a vulnerable Enterprise plugin, and directs readers to DarkEye for full details, without mentioning active exploitation, a PoC, or a patch.

    462124112824.8K
    12.0K followersView on X
  • dbugs@ptdbugs
    Disclosure

    RCE on Grafana via sqlExpressions CVE: CVE-2026-27876 Vendor: Grafana Product: Grafana Enterprise CVSS: 9.1 Credits: n/a Description: A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27876 • https://grafana.com/security/security-advisories/cve-2026-27876 #dbugs_vuln

    Post summary

    The post discloses a RCE vulnerability in Grafana Enterprise via sqlExpressions, urges users to update, and provides technical details but no PoC or exploit code.

    132318710723.4K
    781 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Grafana patches a critical 9.1 RCE (CVE-2026-27876) in SQL expressions that allows SSH hijacking. Update to 12.4.2 now to secure your monitoring host. #Grafana #CyberSecurity #RCE #InfoSec #Monitoring #DevOps #SQLExpressions #Vulnerability #SysAdmin https://securityonline.info/grafana-critical-rce-vulnerability-cve-2026-27876-sql-expressions/ https://t.co/IWd2WlGA9G

    Post summary

    The tweet announces that Grafana has patched the critical CVE‑2026‑27876 RCE and urges users to upgrade to version 12.4.2 to secure their monitoring hosts.

    28029101.7K
    11.0K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Grafanaに重大(Critical)な脆弱性。CVE-2026-27876はCVSSスコア9.1で、SQLから任意ファイルへの書き込みを行えることで任意コート実行が可能なもの。閲覧者以上の権限で悪用可能。DoSのCVE-2026-27880と併せ修正。 https://securityonline.info/grafana-critical-rce-vulnerability-cve-2026-27876-sql-expressions/

    Post summary

    A critical Grafana vulnerability (CVE-2026‑27876) enables arbitrary file writes via SQL leading to RCE, and a patch is available; the linked article details the flaw and fix.

    03041963
    7.3K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Grafana の深刻な脆弱性 CVE-2026-27876/27880 が FIX:RCE と DoS の可能性 https://iototsecnews.jp/2026/03/30/critical-grafana-flaws-allow-attackers-to-achieve-remote-code-execution/ Grafana における 2 件の深刻な脆弱性について解説する記事です。この問題の原因は、SQL クエリを用いたデータ変換機能における不適切なファイル操作の許可と、新機能における認証チェックの欠如にあります。1 つ目の脆弱性 CVE-2026-27876 (CVSS 9.1) は、sqlExpressions という機能における欠陥により、ホスト上のファイル・システムに対して自由にファイルを書き込めてしまうという不備に起因します。それにより、特定のドライバ・ファイルの上書きや、コンフィグ・ファイルの改竄などが可能になってしまいます。 2 つ目の脆弱性 CVE-2026-27880 (CVSS 7.5) は、バージョン 12.1.0 以降に導入された OpenFeature 関連のエンドポイントに存在します。 認証の欠如および入力データに対するサイズ制限の欠如により、攻撃者が送信する大量データがサーバのメモリを枯渇させ、アプリケーション・クラッシュ (DoS) が引き起こされるというものです。ご利用のチームは、ご注意ください。 #CVE202627876 #CVE202627880 #Grafana #Vulnerability

    Post summary

    The article discloses two critical Grafana vulnerabilities (CVE‑2026‑27876 and CVE‑2026‑27880) with technical details, CVSS scores, and notes that fixes are available, but it does not provide proofs of concept, exploit code, or evidence of active exploitation.

    02011160
    481 followersView on X
  • myui@myui
    Disclosure

    n8n、grafanaあたりも脆弱性出てた。 https://cybersecuritynews.com/n8n-vulnerability/ https://nvd.nist.gov/vuln/detail/CVE-2026-27876

    Post summary

    The text simply notes that vulnerabilities exist for n8n and Grafana, citing a news article and the NVD entry for CVE‑2026‑27876.

    03000660
    1.8K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical and High vulnerabilities in #Grafana. #CVE-2026-27876 #CVE-2026-27880. CVSS: 9.1. #CVE-2026-27876 can lead to remote arbitrary code execution, while #CVE-2026-27880 can cause out-of-memory crashes. https://ccb.belgium.be/advisories/warning-remote-code-execution-injection-vulnerabilities-grafana-patch-immediately #Patch #Patch #Patch

    Post summary

    The post alerts users about high‑severity CVEs in Grafana and urges immediate patching, providing CVSS scores and impact details but no evidence of active exploitation or PoC.

    01001258
    7.2K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27876: CRITICAL] Beware of cyber attacks leveraging SQL Expressions in Grafana Enterprise that can result in remote code execution (RCE). Update Grafana to stay protected against this vulnerability.#cve,CVE-2026-27876,#cybersecurity https://cvefind.com/CVE-2026-27876

    Post summary

    The post warns of a critical CVE that allows remote code execution via SQL expressions in Grafana Enterprise and urges users to update their Grafana installation for protection.

    01010101
    617 followersView on X
  • DarkEye@darkeye_team
    Disclosure

    🚨 Detailed Analysis for CVE-2026-27876 (Vulnerability Alert) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! Get the Analysis & Prioritized Asset List now: 🔗 https://www.darkeye.org/vuln/cve/CVE-2026-27876 Critical Unauthenticated RCE! Exploits Grafana's plugin signing bypass to execute arbitrary code without authentication via maliciously crafted plugin archives. cc: @zoomeye_team (83k+ targets detected 🎯 (Early Warning)) #CVE202627876 #CVE #Grafana #RCE #DarkEye #ZoomEye #BugBounty

    Post summary

    The post releases a detailed analysis of CVE‑2026‑27876, outlining a critical unauthenticated RCE via Grafana’s plugin signing bypass, but it does not provide a PoC, exploit code, or patch information.

    00010212
    954 followersView on X
  • dbugs@ptdbugs
    Patch

    @ide9x Security researchers guarding not just vulnerabilities, but broken links too. Updated ref: https://grafana.com/blog/grafana-security-release-critical-and-high-severity-security-fixes-for-cve-2026-27876-and-cve-2026-27880/ We also noticed the dbugs reference went down — working on a fix. Thanks for the bug report!

    Post summary

    The tweet announces a Grafana security release for CVE‑2026‑27876 and CVE‑2026‑27880, noting that patches are available and that the authors are addressing broken links.

    00010551
    758 followersView on X
  • DC3 VDP@DC3VDP
    Disclosure

    APR 2026 @DeptofDefense Vulnerability Disclosure Program #VDP @Hacker0x01 #Hackers reported a critical severity vulnerability identifying a weakness in the sqlExpressions feature of select Grafana instances, CVE-2026-27876. Read all about it in the #Knowledgebyte. https://t.co/IsDOQONM2Z

    Post summary

    The tweet announces a critical vulnerability (CVE‑2026‑27876) affecting Grafana’s sqlExpressions feature, reported by the Dept of Defense VDP and hacker @Hacker0x01, but provides no further technical, exploit, or remediation details.

    00000125
    4.9K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Another critical Grafana security update landed in openSUSE Leap. The RCE (CVE-2026-27876) lets attackers turn Viewer accounts into full host access. Read more -> https://tinyurl.com/mstzsfc3 #openSUSE https://t.co/nWop87JWPj

    Post summary

    openSUSE Leap has released a critical patch for CVE-2026-27876, addressing an RCE that could upgrade Viewer accounts to full host access.

    0000044
    1.5K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Grafana ❗ CVE-2026-27880 ❗ CVE-2026-27876 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-grafana-2/ https://t.co/qnFy1GWDCt

    Post summary

    The tweet notes two Grafana CVE identifiers and links to a webpage for more details, but offers no technical information, mitigation, or exploitation evidence.

    00000108
    6.6K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-27876: Grafana SQL Expressions RCE Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04b0kFj0

    Post summary

    The provided text appears to be the headline of an article about Grafana’s SQL Expressions Remote Code Execution vulnerability, with no explicit technical, PoC, or patch details.

    0000035
    28 followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-27876 In Grafana, chained attack via sqlExpressions and Enterprise plugin enables unauth RCE. Severity: Critical PoC: n/a Exploited: n/a Product: grafana:grafana

    Post summary

    Reports a critical unauthenticated RCE in Grafana’s Enterprise plugin via chained sqlExpressions, without PoC, patch or exploitation details.

    000009
    1 followersView on X
  • Ashraf Zaryouh@0xBlackash
    Patch

    🚨 Critical Alert: CVE-2026-27876 New RCE vulnerability detected. Allows full system compromise via authentication bypass. Patch immediately. 🛡️ https://github.com/0xBlackash/CVE-2026-27876/ ​#CyberSecurity #InfoSec #Grafana https://t.co/SsUrv8tyXZ

    Post summary

    The post alerts of a new RCE vulnerability (CVE‑2026‑27876) that enables authentication bypass and full system compromise, includes a GitHub link likely containing a PoC, and urges immediate patching, with no evidence of active exploitation or debunking.

    00000103
    3 followersView on X
  • CybrPulse@CybrPulse
    Disclosure

    CVE-2026-27876 (CVSS 9.1) in Grafana 11.6.0+: file write via SQL expressions chains to RCE and direct SSH access on the host. Viewer permissions + sqlExpressions = full compromise. Patch now. https://gbhackers.com/critical-grafana-flaws/ #infosec

    Post summary

    CVE‑2026‑27876 in Grafana 11.6.0+ is a high‑severity (CVSS 9.1) RCE vulnerability that allows file writes via SQL expression chains, providing direct SSH access. A patch has been released.

    0000062
    24 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Grafana patches two critical bugs in v12.4.2, including CVE-2026-27876 allowing full remote code execution and SSH access to host servers. https://threatcluster.io/cluster/critical-grafana-vulnerabilities-enable-remote-code-executio-68b208df

    Post summary

    Grafana released v12.4.2 to patch two critical bugs, including CVE-2026-27876 that enabled full remote code execution and SSH access; no PoC or active exploitation is reported.

    0000079
    128 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @the_yellow_fall Your monitoring tool watching every server in the network just became the way in. CVE-2026-27876 - Grafana SQL expression RCE at CVSS 9.1 with SSH hijacking. Compromise the dashboard, own everything it monitors. https://vulntracker.io

    Post summary

    A high‑severity RCE vulnerability (CVE-2026-27876) in Grafana is disclosed, detailing the attack vector and potential SSH hijacking capability.

    00000121
    495 followersView on X
  • StrongKeep Cybersecurity@StrongKeepCyber
    Patch

    Grafana just dropped a critical RCE affecting exposed dashboards. For small teams, patch quickly, rotate credentials, and restrict access to Grafana on public networks—no panic, just practical hardening. Read more: https://securityonline.info/grafana-critical-rce-vulnerability-cve-2026-27876-sql-expressions/

    Post summary

    Grafana CVE-2026-27876 is a critical remote code execution flaw affecting exposed dashboards, prompting users to patch, rotate credentials, and restrict public access.

    0000069
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---

Explore more