← לוח פגיעויות

CVE-2026-33380

בינונית 6.5

תיאור (מקור, אנגלית)

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-4/8/2026
CWE
CWE-552

מוצרים מושפעים

grafana: grafana

קישורים