Looking for the vulnerability index of Invicti's legacy products?
Grafana Files or Directories Accessible to External Parties Vulnerability (CVE-2026-33380) - Vulnerability Database

Grafana Files or Directories Accessible to External Parties Vulnerability (CVE-2026-33380)

Description

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

References