CVE-2026-28381
Received
Received - Intake
Snowflake Datasource File Read/Write Vulnerability in Grafana
Publication date: 2026-06-22
Last updated on: 2026-06-22
Assigner: Grafana Labs
Description
Description
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| grafana | grafana | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |