Grafana security release: critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880.
Article excerpt
Highlighted: the sentence this signal was extracted from
Grafana security release: critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880. 2026-03-25 - 5 min Today Grafana Labs is releasing Grafana 12.4.2 along with patches for Grafana 12.3, 12.2, 12.1, and 11.6, which include critical and high severity security fixes. Grafana Labs recommend that you install the newly released versions as soon as possible. Grafana 12.4.2 with security fixes: Grafana 12.3.6 with security fixes: Grafana 12.2.8 with security fixes: Grafana 12.1.10 with security fixes: Grafana 11.6.14 with security fixes: As per its security policy, Grafana Labs customers have received security patched versions two weeks in advance under embargo, and Grafana Cloud has been patched. Grafana Labs has also coordinated closely with all cloud providers licensed to offer Grafana Cloud. They received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana. CVE-2026-27876: SQL expressions arbitrary file write enabling remote code execution. Grafana's SQL expressions feature enables transforming query data with familiar SQL syntax. This syntax, however, also permitted writing arbitrary files to the file system in such a way that one could chain several attack vectors to achieve remote code execution. The CVSS score...
Keep reading with a free account
The rest of this article, and every signal for Grafana Labs, is in your free account.
