Detects Grafana instances running versions 11.6.0 through 12.4.1 where the SQL Expressions feature permits SELECT...INTO clauses, enabling authenticated users to write arbitrary files to the server filesystem. By overwriting a Sqlyze driver or AWS data source configuration, an attacker can achieve full remote code execution. Requires Viewer permissions and the sqlExpressions feature toggle to be enabled. Update to Grafana 12.4.2 or later.
Is your app exploitable through CVE-2026-27876?
Scan your domain free