
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27876 is a code injection vulnerability in Grafana that enables a chained attack via SQL Expressions and a Grafana Enterprise plugin, resulting in remote arbitrary code execution (RCE). It was published on March 27, 2026, and affects Grafana versions 11.6.0–11.6.13, 12.0.0–12.1.9, 12.2.0–12.2.7, 12.3.0–12.3.5, and 12.4.0–12.4.1; versions 11.5 and below, 12.0 (EOL), and 13.0.0+ are not affected. Only instances with the sqlExpressions feature toggle enabled are vulnerable. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (Grafana Advisory, Grafana Blog).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The attack chain involves a high-privileged authenticated user crafting malicious SQL Expressions that, when processed by Grafana's SQL Expressions feature toggle, interact with a Grafana Enterprise plugin in a way that allows arbitrary code to be executed on the server. Exploitation requires network access, high privileges, no user interaction, and the sqlExpressions feature toggle to be enabled; the scope is changed, meaning impact extends beyond the vulnerable component itself. No concrete public exploit payload or step-by-step attack sequence has been published — only a vulnerability detection/scanning script is publicly available (GitHub PoC Checker, Grafana Advisory).
Successful exploitation allows a high-privileged attacker to execute arbitrary code remotely on the Grafana server, resulting in full system compromise with high impact to confidentiality, integrity, and availability. An attacker gaining code execution on the Grafana server could exfiltrate sensitive dashboard data, credentials, and connected data source secrets, and potentially pivot to other internal systems. The changed scope means the impact extends beyond Grafana itself to the underlying host and connected infrastructure (Grafana Advisory, CyberSecurityNews).
No confirmed working exploit or in-the-wild exploitation has been reported. A public GitHub repository contains a vulnerability detection/scanning script (CVE-2026-27876-check.py) that identifies vulnerable Grafana instances but does not provide actual exploitation code or attack steps (GitHub PoC Checker). The EPSS score is approximately 0.079%, indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report. Qualys has published detection plugins (IDs 733903, 531116, 762953, 762951) for this vulnerability.
curl, wget, or reverse shell processes).Grafana has released patched versions addressing this vulnerability: 11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2, and all 13.0.0+ releases. Organizations unable to upgrade immediately should disable the sqlExpressions feature toggle on all Grafana instances as a temporary workaround. Additionally, restricting administrative access to Grafana to trusted users only reduces the attack surface, since exploitation requires high privileges. Monitoring for suspicious SQL expression activity and unauthorized code execution attempts is also recommended (Grafana Advisory, Grafana Blog).
Grafana published both a dedicated security advisory and a blog post announcing critical and high severity fixes for CVE-2026-27876 alongside CVE-2026-27880 (Grafana Blog). The vulnerability received coverage from multiple security news outlets including GBHackers, CyberSecurityNews, and Security Boulevard, highlighting the RCE risk (CyberSecurityNews, SecurityOnline). The Belgian Centre for Cybersecurity (CCB) issued a warning urging immediate patching. Community discussion appeared on Reddit's r/blueteamsec and Bluesky, with general consensus emphasizing the importance of upgrading or disabling the feature toggle. CyCognito published a threat analysis blog post covering the emerging threat (CyCognito Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."