CVE-2026-33375
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-33375 is a logic flaw in the Grafana MSSQL data source plugin that allows a low-privileged Viewer-role user to bypass API restrictions and trigger uncontrolled memory exhaustion (Out-Of-Memory), crashing the host container. The vulnerability was published on March 26, 2026, and affects Grafana OSS versions 11.6.0–11.6.13, 12.1.0–12.1.9, 12.2.0–12.2.7, 12.3.0–12.3.5, and 12.4.0–12.4.1. It carries a CVSS v3.1 base score of 6.5 (Medium/High) (Grafana Advisory, EUVD).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption). The MSSQL data source plugin contains a logic flaw that fails to properly enforce API access controls for Viewer-role users, allowing them to submit requests that trigger unbounded memory allocation within the Grafana process. The attack is network-based, requires only low privileges (a valid Viewer account), and no user interaction, making it straightforward to trigger remotely. No public proof-of-concept code has been identified at this time (Grafana Advisory).

Impact

Successful exploitation causes catastrophic memory exhaustion (OOM) that crashes the Grafana host container, resulting in a complete denial of service for all users of the affected Grafana instance. There is no impact on data confidentiality or integrity — the vulnerability is purely an availability issue. Because the crash affects the entire container, all dashboards, alerts, and monitoring functions become unavailable until the service is restarted (Grafana Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting. The EPSS score is approximately 0.013% (0.000130), indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low privilege requirement (any Viewer account) lowers the barrier for exploitation in environments with broad user access (Grafana Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Grafana instance running an affected version (11.6.0–11.6.13, 12.1.0–12.1.9, 12.2.0–12.2.7, 12.3.0–12.3.5, or 12.4.0–12.4.1) with the MSSQL data source plugin configured.
  2. Obtain Viewer credentials: Acquire or register a low-privileged Viewer account on the target Grafana instance (e.g., via self-registration if enabled, or compromised credentials).
  3. Identify the vulnerable API endpoint: Locate the MSSQL data source API endpoint that is insufficiently restricted for Viewer-role users.
  4. Send crafted API request: Submit a specially crafted request to the MSSQL plugin API endpoint that bypasses the intended access controls and triggers unbounded memory allocation within the Grafana process.
  5. Trigger OOM crash: Repeat or sustain the request as needed to exhaust available memory, causing the Grafana host container to crash and become unavailable to all users (Grafana Advisory).

Indicators of compromise

  • Logs: Grafana application logs showing repeated API requests to MSSQL data source endpoints from a Viewer-role account; OOM killer messages in system/container logs (e.g., kernel: Out of memory: Kill process or Docker/Kubernetes OOM events).
  • Network: Unusual volume of API requests targeting MSSQL data source plugin endpoints from a single low-privileged user account.
  • Process/Container: Unexpected Grafana container restarts or crashes; container orchestration (Kubernetes, Docker) logs showing OOM-related container termination events.
  • Metrics: Sudden spike in Grafana process memory consumption visible in host or container monitoring dashboards immediately preceding a crash.

Mitigation and workarounds

Grafana has released patched versions addressing this vulnerability. Users should upgrade to the following fixed releases: 11.6.14+security-01 (for 11.6.x), 12.1.10+security-01 (for 12.1.x), 12.2.8+security-01 (for 12.2.x), 12.3.6+security-01 (for 12.3.x), and 12.4.2 (for 12.4.x). As interim mitigations, administrators should restrict Viewer role permissions where possible, audit user accounts with Viewer access, and monitor Grafana container memory usage for unusual spikes. Disabling or removing the MSSQL data source plugin if not required can also eliminate the attack surface (Grafana Advisory, SUSE Advisory).

Community reactions

SUSE issued security update announcements (SUSE-SU-2026:2258-1 and SUSE-SU-2026:2265-1) addressing this and related Grafana vulnerabilities for their enterprise Linux distributions (SUSE Advisory). The FreeBSD VuXML database also catalogued the vulnerability, and the fix was tracked in FreeBSD ports (FreeBSD VuXML). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76844HIGH8.3
  • Grafana logoGrafana
  • grafana-elasticsearch
NoNoAug 24, 2026
CVE-2026-76172HIGH7.5
  • Grafana logoGrafana
  • aspnetcore-runtime-dbg-8.0
NoNoAug 24, 2026
CVE-2026-75975HIGH7.5
  • Grafana logoGrafana
  • cockpit-image-builder
NoNoAug 24, 2026
CVE-2026-17033MEDIUM6.8
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoNoAug 24, 2026
CVE-2026-19197MEDIUM6.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesAug 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management