CVE-2026-28381
Received Received - Intake
Snowflake Datasource File Read/Write Vulnerability in Grafana

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: Grafana Labs

Description
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
grafana grafana *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves the Snowflake datasource in Grafana, which allows GET and PUT commands. This means that any user who has access to run queries against the data source can read and write files between the local Grafana server and the connected Snowflake host.

Impact Analysis

The vulnerability can have a significant impact because it allows users with query access to read and write files on the local Grafana server and the Snowflake host. This can lead to unauthorized data exposure and modification, potentially compromising the confidentiality and integrity of sensitive information.

Compliance Impact

The vulnerability allows any user with access to the Snowflake datasource in Grafana to execute GET/PUT commands, enabling them to read and write files between the local Grafana server and the connected Snowflake host.

This unauthorized ability to read and write data could lead to exposure or modification of sensitive information, which may violate data protection requirements under regulations such as GDPR and HIPAA.

Therefore, this vulnerability poses a significant risk to compliance with common standards and regulations that mandate strict controls over data confidentiality and integrity.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-28381. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart