Skip to main content
Grafana LabsLaunch

Grafana security release: critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880.

What happened

Grafana Labs launches Grafana 12.4.2.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Grafana security release: critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880. 2026-03-25 - 5 min Today Grafana Labs is releasing Grafana 12.4.2 along with patches for Grafana 12.3, 12.2, 12.1, and 11.6, which include critical and high severity security fixes. Grafana Labs recommend that you install the newly released versions as soon as possible. Grafana 12.4.2 with security fixes: Grafana 12.3.6 with security fixes: Grafana 12.2.8 with security fixes: Grafana 12.1.10 with security fixes: Grafana 11.6.14 with security fixes: As per its security policy, Grafana Labs customers have received security patched versions two weeks in advance under embargo, and Grafana Cloud has been patched. Grafana Labs has also coordinated closely with all cloud providers licensed to offer Grafana Cloud. They received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana. CVE-2026-27876: SQL expressions arbitrary file write enabling remote code execution. Grafana's SQL expressions feature enables transforming query data with familiar SQL syntax. This syntax, however, also permitted writing arbitrary files to the file system in such a way that one could chain several attack vectors to achieve remote code execution. The CVSS score...

Keep reading with a free account

The rest of this article, and every signal for Grafana Labs, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Product
Grafana 12.4.2

The full record

From the Signal API record

Details

Category
Launches

Extraction

Confidence
40%
Detected
Mar 25, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Grafana Labs and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Grafana Labs this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/97ac85c9-cf3f-4bab-886d-591f0a81d63a returns this record as JSON. POST /v1/companies/enrich returns every signal for grafana.com.

{
  "signal_id": "97ac85c9-cf3f-4bab-886d-591f0a81d63a",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-03-25T00:00:00+00:00",
  "company": {
    "name": "Grafana Labs",
    "domain": "grafana.com"
  },
  "data": {
    "url": "https://grafana.com/blog/grafana-security-release-critical-and-high-severity-security-fixes-for-cve-2026-27876-and-cve-2026-27880",
    "title": "Grafana security release: critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880.",
    "excerpt": "Grafana security release: critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880.\n\n2026-03-25 - 5 min\n\nToday Grafana Labs is releasing Grafana 12.4.2 along with patches for Grafana 12.3, 12.2, 12.1, and 11.6, which include critical and high severity security fixes. Grafana Labs recommend that you install the newly released versions as soon as possible.\n\nGrafana 12.4.2 with security fixes:\n\nGrafana 12.3.6 with security fixes:\n\nGrafana 12.2.8 with security fixes:\n\nGrafana 12.1.10 with security fixes:\n\nGrafana 11.6.14 with security fixes:\n\nAs per its security policy, Grafana Labs customers have received security patched versions two weeks in advance under embargo, and Grafana Cloud has been patched.\n\nGrafana Labs has also coordinated closely with all cloud providers licensed to offer Grafana Cloud. They received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana.\n\nCVE-2026-27876: SQL expressions arbitrary file write enabling remote code execution.\n\nGrafana's SQL expressions feature enables transforming query data with familiar SQL syntax. This syntax, however, also permitted writing arbitrary files to the file system in such a way that one could chain several attack vectors to achieve remote code execution.\n\nThe CVSS score...",
    "product": "Grafana 12.4.2",
    "summary": "Grafana Labs launches Grafana 12.4.2.",
    "category": "launches",
    "found_at": "2026-03-25T00:00:00Z",
    "planning": false,
    "image_url": "https://a-us.storyblok.com/f/1022730/b99d8b21fc/grafana-security-fix.png",
    "confidence": 0.4038,
    "product_data": {
      "full_text": "Grafana 12.4.2",
      "fuzzy_match": true
    },
    "published_at": "2026-03-25T00:00:00Z",
    "article_sentence": "Grafana Labs is releasing Grafana 12.4.2 along with patches for Grafana 12.3, 12.2, 12.1, and 11.6, which include critical and high severity security fixes."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.