CVE-2026-28381
Critical · CVSS 9.6Grafana Snowflake datasource plugin — Improper Access Control - arbitrary file read/write via Snowflake GET/PUT commands
- CVSS
- 9.6
- nvd
- EPSS
- 0.21%
- 11th pct
- KEV
- No
- Class
- other
- CWE-284
Description
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
Search profile — drives PoC discovery
Symbols GETPUTSnowflake datasourcerun querieslocal grafana serverSnowflake host
Keywords CVE-2026-28381Grafana Snowflake datasourceGET PUT command file read writeGrafana Snowflake arbitrary fileCWE-284 GrafanaSnowflake plugin file exfiltrationGrafana datasource improper access control
References
Status: enriched · ingested 2026-06-30T18:00:22.000Z · profiled 2026-07-01T06:30:14.000Z