Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-28381 -- CVSS 9.6 Vulnerability Briefing

CVE-2026-28381 | CVSS 9.6 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-28381 is an unauthorized file read/write vulnerability in the Grafana Snowflake datasource plugin, which permits any user with query execution access to leverage Snowflake's native GET and PUT commands to transfer files between the Grafana server's local filesystem and the connected Snowflake environment.

Technical Detail

The flaw exists because the Grafana Snowflake datasource plugin does not restrict or sanitize the use of Snowflake's GET and PUT stage commands, which are intended for file staging operations but are exposed to any authenticated query user without additional authorization controls. An attacker with legitimate query access to the datasource can craft GET or PUT commands to read arbitrary files from the local Grafana server filesystem or write attacker-controlled files to it, potentially enabling credential theft, configuration exfiltration, or planting of malicious content. The impact includes unauthorized data exfiltration from the host system and potential for further compromise depending on what files are accessible or writable in the Grafana server's operating context.

Exploitation Status

No known exploit code has been publicly observed as of June 29, 2026. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, and there is no confirmed evidence of active exploitation in the wild. The exploit maturity is assessed as no known exploit at this time, though the CVSS score of 9.6 Critical reflects the severity of impact if the vulnerability were to be weaponized.

Who Is Targeting This

No confirmed threat actor attribution has been established for this vulnerability. Reported (research-inferred) associations at medium confidence include DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET, though no origin, motivation, or campaign context has been confirmed for any of these actors in relation to CVE-2026-28381. These associations should be treated as preliminary and unverified. The data also explicitly notes no public attribution, and these actor names should not be treated as confirmed targeting without corroborating evidence.

What To Do

Organizations running Grafana with the Snowflake datasource plugin should treat this as a high-priority remediation item given the critical CVSS score. Apply any available patch or updated plugin version from Grafana Labs immediately upon release, and monitor the Grafana security advisories channel for patch availability. As an interim workaround, restrict query execution permissions on the Snowflake datasource to the minimum necessary set of trusted users, and audit existing datasource access controls to identify over-privileged accounts. Where possible, configure Snowflake roles used by the Grafana integration to explicitly deny GET and PUT command privileges at the database role level. Detection efforts should focus on monitoring Grafana query logs for GET and PUT command strings originating from datasource queries, and reviewing Snowflake audit logs for unexpected stage file transfer activity associated with the Grafana service account.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →