Loading market data...
← Back to CVE feed

CVE-2026-33380

MEDIUM CVSS 6.3 View on NVD ↗

Description

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Published: May 13, 2026 20:16 UTC Modified: May 14, 2026 16:21 UTC