Security Advisory

CVE-2026-33380

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 19:28:32
Last updated 2026-07-24 12:23:15
Assigner GRAFANA
CVSS score 6.3
State PUBLISHED

Description

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.