Grafana SQL Expressions Arbitrary File Read Vulnerability

Vulnerability

A vulnerability exists in Grafana's SQL Expressions feature, allowing authenticated attackers to read arbitrary files from the server's filesystem. This issue affects only instances with the sqlExpressions feature toggle enabled.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the Grafana server.

Added: May 13, 2026, 8:27 PM
Updated: May 13, 2026, 8:27 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
2.5
exploitability
5.2
remediation
8.3
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.