CVE-2026-27880Patch(grafana / grafana)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch grafana grafana systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-125CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-27); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
grafana

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-04-03: 1Mentions · 2026-04-10: 1Patch / Workaround · 2026-03-27: 2Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-03: 103-2703-2803-3004-0304-10
Signal classification3 categories
Patch
457.1%
Disclosure
228.6%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure1Patch2
2026-03-281
Patch1
2026-03-301
Patch1
2026-04-031
Disclosure1
2026-04-101
General1
Full discourse7 posts
  • iototsecnews@iototsecnews
    Disclosure

    Grafana の深刻な脆弱性 CVE-2026-27876/27880 が FIX:RCE と DoS の可能性 https://iototsecnews.jp/2026/03/30/critical-grafana-flaws-allow-attackers-to-achieve-remote-code-execution/ Grafana における 2 件の深刻な脆弱性について解説する記事です。この問題の原因は、SQL クエリを用いたデータ変換機能における不適切なファイル操作の許可と、新機能における認証チェックの欠如にあります。1 つ目の脆弱性 CVE-2026-27876 (CVSS 9.1) は、sqlExpressions という機能における欠陥により、ホスト上のファイル・システムに対して自由にファイルを書き込めてしまうという不備に起因します。それにより、特定のドライバ・ファイルの上書きや、コンフィグ・ファイルの改竄などが可能になってしまいます。 2 つ目の脆弱性 CVE-2026-27880 (CVSS 7.5) は、バージョン 12.1.0 以降に導入された OpenFeature 関連のエンドポイントに存在します。 認証の欠如および入力データに対するサイズ制限の欠如により、攻撃者が送信する大量データがサーバのメモリを枯渇させ、アプリケーション・クラッシュ (DoS) が引き起こされるというものです。ご利用のチームは、ご注意ください。 #CVE202627876 #CVE202627880 #Grafana #Vulnerability

    Post summary

    The post delivers a technical disclosure of two critical Grafana flaws (CVE‑2026‑27876 and CVE‑2026‑27880), outlining their RCE and DoS vectors and CVSS scores, but offers no PoC, exploit code, active attack evidence, or patch notice.

    02011160
    481 followersView on X
  • dbugs@ptdbugs
    Disclosure

    OpenFeature evaluation API reads input data with no bounds CVE: CVE-2026-27880 Vendor: Grafana Product: Grafana CVSS: 7.5 Credits: n/a Description: The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27880 • https://grafana.com/security/security-advisories/cve-2026-27880 #dbugs_vuln

    Post summary

    The text announces the discovery of CVE‑2026‑27880 in Grafana’s OpenFeature API, detailing an out‑of‑memory issue without providing a PoC, exploit, or evidence of active exploitation.

    01021244
    781 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical and High vulnerabilities in #Grafana. #CVE-2026-27876 #CVE-2026-27880. CVSS: 9.1. #CVE-2026-27876 can lead to remote arbitrary code execution, while #CVE-2026-27880 can cause out-of-memory crashes. https://ccb.belgium.be/advisories/warning-remote-code-execution-injection-vulnerabilities-grafana-patch-immediately #Patch #Patch #Patch

    Post summary

    The advisory warns of two critical Grafana vulnerabilities, gives CVSS and impact details, and urges immediate patching through the provided link.

    01001258
    7.2K followersView on X
  • dbugs@ptdbugs
    Patch

    @ide9x Security researchers guarding not just vulnerabilities, but broken links too. Updated ref: https://grafana.com/blog/grafana-security-release-critical-and-high-severity-security-fixes-for-cve-2026-27876-and-cve-2026-27880/ We also noticed the dbugs reference went down — working on a fix. Thanks for the bug report!

    Post summary

    Grafana has released critical and high severity fixes for CVE‑2026‑27876 and CVE‑2026‑27880, with a working fix underway for a related broken‑link issue.

    00010551
    758 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Grafana ❗ CVE-2026-27880 ❗ CVE-2026-27876 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-grafana-2/ https://t.co/qnFy1GWDCt

    Post summary

    A tweet announces two new Grafana CVEs and links to a CERT advisory for more information, but provides no technical or exploit details.

    00000108
    6.6K followersView on X
  • Kwaza ICT@KwazaIct
    Patch

    Grafana users: Critical security fixes released for CVE-2026-27876 & CVE-2026-27880. Update your instances immediately to protect your data. Don't delay! #DevOps #Security

    Post summary

    Grafana has released critical security fixes for CVE‑2026‑27876 and CVE‑2026‑27880, urging users to update immediately to protect data.

    0000066
  • Autumn Good@autumn_good_35
    Patch

    条件 Access to execute data source queries (Viewer permissions or higher) The sqlExpressions feature toggle must be enabled on the Grafana instance. Grafana security release: Critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880 https://grafana.com/blog/grafana-security-release-critical-and-high-severity-security-fixes-for-cve-2026-27876-and-cve-2026-27880/

    Post summary

    Grafana has released critical and high severity fixes for CVE‑2026‑27876 and CVE‑2026‑27880, indicating the availability of patches to address these vulnerabilities.

    00000653
    6.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---

Explore more