
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27879 is a denial-of-service vulnerability in Grafana that allows authenticated attackers to trigger out-of-memory crashes via specially crafted resample queries. It was published on March 27, 2026, and affects Grafana versions below 8.0.0, versions 8.0.0 through 11.6.13, 12.0.0 through 12.1.9, 12.2.0 through 12.2.7, 12.3.0 through 12.3.5, and 12.4.0 through 12.4.1. It carries a CVSS v3.1 base score of 6.5 (Medium/High) (Grafana Advisory, ENISA EUVD).
The vulnerability is rooted in uncontrolled resource consumption (CWE-400) and potentially out-of-bounds write behavior (CWE-787) within Grafana's resample query processing logic. An authenticated user with low privileges can submit a crafted resample query over the network — requiring no user interaction — that causes the Grafana process to exhaust available memory and crash. The attack vector is network-based with low complexity, meaning no special conditions or chained vulnerabilities are required beyond valid credentials (Grafana Advisory, ENISA EUVD).
Successful exploitation results in complete availability loss for the affected Grafana instance, causing it to crash and become unreachable. There is no impact on confidentiality or data integrity — the attack is purely a denial-of-service condition. Organizations relying on Grafana for monitoring, alerting, or observability dashboards would experience full service disruption until the instance is restarted, potentially masking other infrastructure issues during the outage (Grafana Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Grafana Advisory). The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/api/health.dmesg or /var/log/syslog) referencing the Grafana process.top, htop, Prometheus node exporter metrics) immediately preceding a crash.Grafana has released patched versions addressing this vulnerability. Users should upgrade to one of the following fixed releases: v11.6.14 (for versions 8.0.0–11.x), v12.1.10 (for 12.0.0–12.1.x), v12.2.8 (for 12.2.x), v12.3.6 (for 12.3.x), or v12.4.2 (for 12.4.x). As interim mitigations, administrators should restrict API access to trusted users and networks, monitor for unusual memory consumption patterns, and consider limiting who can execute resample queries at the application or network level (Grafana Advisory, SUSE Advisory).
SUSE issued security update announcements (SUSE-SU-2026:2258-1 and SUSE-SU-2026:2265-1) addressing this and related Grafana vulnerabilities for their enterprise Linux distributions (SUSE Advisory). The vulnerability was also tracked by Tenable (Nessus plugin 304079) and indexed by FreeBSD Ports and OpenSUSE security mailing lists. No significant social media discussion or notable independent researcher commentary has been identified beyond standard vulnerability database entries.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."