PT-2026-51302 · Grafana · Snowflake Datasource Plugin+1

·

CVE-2026-28381

·

Published

2026-06-22

·

Updated

2026-06-22

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grafana with Snowflake datasource plugin (affected versions not specified)
Description The Snowflake datasource allows the use of GET and PUT commands. This enables any user with access to run queries against the data source to read and write arbitrary files between the local Grafana server and the connected Snowflake host.
Recommendations Update the Snowflake datasource plugin. Restrict access to the datasource to minimize the risk of exploitation.

Fix

LPE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28381

Affected Products

Grafana
Snowflake Datasource Plugin