Grafana issued urgent patches for two high-severity vulnerabilities, including CVE-2026-27876, a critical flaw in the SQL Expressions feature that can allow an attacker with Viewer privileges or higher to write arbitrary files to the server and potentially escalate to full remote code execution. The issue can be chained into broader compromise scenarios, including unauthorized SSH access, prompting public warnings from national defenders such as Belgium’s CCB to patch immediately.
Grafana also fixed CVE-2026-27880, which affects OpenFeature validation endpoints and allows unauthenticated attackers to crash vulnerable instances by sending oversized requests that exhaust memory. Grafana Labs said patched releases, including 12.4.2, are available and noted that Amazon Managed Grafana and Azure Managed Grafana were already protected under embargo; for temporary mitigation, administrators were advised to disable the sqlExpressions feature toggle and use highly available deployments and reverse proxies such as Nginx or Cloudflare to restrict request sizes.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Alongside the fixes, Grafana advised administrators who could not patch immediately to disable the sqlExpressions feature toggle and use highly available deployments and reverse proxies such as Nginx or Cloudflare to limit DoS payload sizes.
Belgium's Centre for Cybersecurity Belgium published an advisory warning about remote code execution and injection vulnerabilities in Grafana and urged organizations to patch immediately.
Grafana noted that Amazon Managed Grafana and Azure Managed Grafana were already protected before public disclosure under embargo. This indicated coordinated pre-release mitigation for major managed service providers.
Grafana released urgent security updates, including version 12.4.2, to fix CVE-2026-27876 and CVE-2026-27880. The flaws could allow remote code execution via the SQL Expressions feature and unauthenticated denial-of-service through oversized requests to OpenFeature validation endpoints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceccb.belgium.be
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.