๐Ÿ” CVE Alert

CVE-2026-28381

CRITICAL 9.6

Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT

CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.

Vendor grafana
Product snowflake datasource
Ecosystems
Industries
Technology
Published Jun 22, 2026
Last Updated Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for grafana snowflake datasource

Be the first to know when new critical vulnerabilities affecting grafana snowflake datasource are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Grafana / Snowflake Datasource
1.14.7 โ‰ค 1.14.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
grafana.com: https://grafana.com/security/security-advisories/cve-2026-28381

Credits

stargravy (Researcher)