CVE-2026-27876
Last modified
CVE-2026-27876 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. Only instances in the following version ranges are affected: - 11.6.0 (inclusive) to 11.6.14 (exclusive): 11.6.14 has the fix. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. Only instances in the following version ranges are affected: - 11.6.0 (inclusive) to 11.6.14 (exclusive): 11.6.14 has the fix. 11.5 and below are not affected. - 12.0.0 (inclusive) to 12.1.10 (exclusive): 12.1.10 has the fix. 12.0 did not receive an update, as it is end-of-life. - 12.2.0 (inclusive) to 12.2.8 (exclusive): 12.2.8 has the fix. - 12.3.0 (inclusive) to 12.3.6 (exclusive): 12.3.6 has the fix. - 12.4.0 (inclusive) to 12.4.2 (exclusive): 12.4.2 has the fix. 13.0.0 and above also have the fix: no v13 release is affected.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Grafana | Grafana | < 11.6.0 |
| Grafana | Grafana | >= 11.6.14, < 12.0.0 |
| Grafana | Grafana | >= 12.1.10, < 12.2.0 |
| Grafana | Grafana | >= 12.2.8, < 12.3.0 |
| Grafana | Grafana | >= 12.3.6, < 12.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-27876?
How severe is CVE-2026-27876?
How do I fix CVE-2026-27876?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2786Use-after-free in the JavaScript Engine component. This vuln…9.8
- CVE-2026-27860If auth_username_chars is empty, it is possible to inject ar…5.3
- CVE-2026-27868An attacker with access via network to the Regesta Smart HD-…6.9
- CVE-2026-27869An attacker with access via network to the Regesta Smart HD-…6.9
- CVE-2026-2787Use-after-free in the DOM: Window and Location component. Th…9.8
- CVE-2026-27870An attacker with access via network to the Regesta Smart HD-…4.8
- CVE-2026-27877When using public dashboards and direct data-sources, all di…7.5
- CVE-2026-27878A TraceQL query in Grafana Tempo with a large exemplars hint…6.5
- CVE-2026-27879A resample query can be used to trigger out-of-memory crashe…6.5
- CVE-2026-2788Incorrect boundary conditions in the Audio/Video: GMP compon…9.8
- CVE-2026-27880The OpenFeature feature toggle evaluation endpoint reads unb…7.5
- CVE-2026-27881Coolify is an open-source and self-hostable tool for managin…5
Are you affected by CVE-2026-27876?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
