CVE-2026-28381General(grafana / snowflake)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch grafana snowflake systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • snowflake

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-06-22); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
snowflake

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-22: 3Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-06-22: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 206-2207-06
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-223
Disclosure1General1Patch1
2026-07-061
General1
Full discourse4 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Grafana ❗ CVE-2026-42129 ❗ CVE-2026-42127 ❗ CVE-2026-28381 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-grafana-3/ https://t.co/v2oT4mgkhB

    Post summary

    The tweet lists three Grafana-related CVE identifiers and directs readers to external URLs for more information, but provides no technical details or actionable guidance within the post itself.

    00020242
    6.7K followersView on X
  • VulDB 🛡@vuldb
    General

    Attention, elevated activities detected targeting Grafana Snowflake Datasource (CVE-2026-28381) https://vuldb.com/vuln/372678/cti

    Post summary

    The post alerts on heightened activity targeting Grafana Snowflake Datasource CVE‑2026‑28381 but offers no technical, exploit, or mitigation details.

    01010105
    2.2K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-28381 - Critical supply chain attack in #Grafana. Snowflake datasource GET/PUT commands allow file read/write between server and host. #CVSS 9.6. Restrict access immediately. #CVE @grafana #InfoSec #linux #devsecops #devops #sysadmin More info: https://www.valtersit.com/cve/CVE-2026-28381/

    Post summary

    The tweet alerts to a critical supply‑chain vulnerability in Grafana (CVE-2026-28381) that enables file read/write via Snowflake datasource commands, and links to a page for more details.

    0000068
    958 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Grafana Snowflake Datasource Arbitrary File Read/Write (CVE-2026-28381) The Snowflake datasource in Grafana allows GET/PUT commands. Any user with query access to the datasource can read and write arbitrary files between the Grafana server and the connected Snowflake host. Severity: Critical (CVSS 9.6) 👉Affected: Grafana with Snowflake datasource plugin Action: Update the Snowflake datasource plugin or restrict datasource access.

    Post summary

    The post announces a critical CVE in Grafana’s Snowflake datasource that allows arbitrary file read/write via GET/PUT commands, urging users to update the plugin or limit access.

    0000083
    226 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanasnowflake---

Explore more