Grafana Labs has released security patches for Grafana 12.4.2, 12.3, 12.2, 12.1, and 11.6 addressing two vulnerabilities. CVE-2026-27876 (CVSS 9.1 CRITICAL) allows arbitrary file writes via the SQL expressions feature, enabling remote code execution including SSH access to the host — affecting v11.6.0 and later with the
Table of contents
CVE-2026-27876: SQL expressions arbitrary file write enabling remote code executionImpactImpacted versionsSolutions and mitigationsCVE-2026-27880: Unauthenticated denial-of-service via OpenFeature endpointImpactImpacted versionsSolutions and mitigationsTimeline and post-incident reviewAcknowledgementsReporting security issuesSecurity announcementsSort: