Grafana Security Updates – 31 March 2026

Grafana has released security updates to fix several vulnerabilities across multiple Grafana products.

The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass authorization controls, disclose sensitive datasource configurations, perform cross-site scripting (XSS) attacks via Grafana Explore, or cause denial-ofservice attacks on the affected systems.

Sample of the addressed vulnerabilities:

1. RCE on Grafana via sqlExpressions Vulnerability (CVE-2026-27876):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Remote Code Execution

2. OpenFeature Evaluation API Reads Input Data with No Bounds Vulnerability (CVE-2026-27880):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial-of-Service

Sample of the affected products:

  • Grafana Enterprise.
  • Grafana SQL Expressions.
  • Grafana Testdata Datasource.
  • Grafana MSSQL Data Source Plugin.
Vulnerabilities
  • CVE-2026-28375
  • CVE-2026-27880
  • CVE-2026-27877
  • CVE-2026-27879
  • CVE-2026-27876
  • CVE-2026-33375
  • CVE-2026-21724
  • CVE-2026-21725
  • CVE-2026-21722
  • CVE-2025-41117
  • CVE-2026-21727
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Grafana Security Advisory

References