Improper access control in Grafana - CVE-2026-33380

 

Improper access control in Grafana - CVE-2026-33380

Published: May 18, 2026


Vulnerability identifier: #VU131640
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33380
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in SQL Expressions when evaluating user-supplied SQL expressions. A remote user can read arbitrary files from the server filesystem to disclose sensitive information.

Only instances with the sqlExpressions feature toggle enabled are vulnerable.


Affected software

Grafana

How to mitigate CVE-2026-33380

Install security update from vendor's website.

Grafana - addressed in versions 11.6.14+security-04, 12.2.8+security-04, 12.3.6+security-04, 12.4.3+security-02, 13.0.1+security-01

External References

Related Security Bulletins