Boletines de Vulnerabilidades

CVE-2026-33380

   
Software afectado GRAFANA
 
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-33380