← Vulnerability feed

Vulnerability record · CVE-2024-9264 · published 18 October 2024

CVE-2024-9264: Grafana SQL Expressions feature allows command injection and file read

Grafana · Grafana

Grafana's experimental SQL Expressions feature evaluates duckdb queries containing user input without sufficient sanitization, enabling command injection and local file inclusion. Any authenticated user with VIEWER permission or higher can trigger it, making it a serious risk for multi-tenant or broadly accessible Grafana instances. The duckdb binary must be present in Grafana's $PATH, and it is not installed by default.

9.4 CVSS 4.0 Critical EPSS 95% · top 0.1% CWE-94 · Code injectionCWE-77 · Command injection
9.4CVSS 4.0 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCritical CVSS 9.4 and near-top EPSS score, but exploitation requires authentication and the non-default duckdb binary, lowering real-world reachability.

What it is

Grafana's experimental SQL Expressions feature evaluates duckdb queries containing user input without sufficient sanitization, enabling command injection and local file inclusion. Any authenticated user with VIEWER permission or higher can trigger it, making it a serious risk for multi-tenant or broadly accessible Grafana instances. The duckdb binary must be present in Grafana's $PATH, and it is not installed by default.

Impact

An attacker gains arbitrary command execution on the Grafana host and can read local files, with high confidentiality, integrity and availability impact across the vulnerable component and connected systems. This can lead to full host compromise and access to Grafana data sources and credentials.

Attack surface

Reached over the network through the SQL Expressions feature by an authenticated user holding VIEWER or higher permission; no user interaction is required. The attack only works if the duckdb binary is installed and available in Grafana's $PATH.

Exploitation

Not listed in CISA KEV and no public exploit reference is tagged, but EPSS is very high at 0.94864 (99.856th percentile), indicating strong predicted exploitation activity. No ransomware group usage is documented.

What to do

  • Upgrade Grafana to a version that fixes CVE-2024-9264 per the vendor advisory
  • Disable the experimental SQL Expressions feature if it is not required
  • Remove the duckdb binary from Grafana's $PATH or avoid installing it where SQL Expressions is enabled
  • Restrict Grafana accounts to the minimum permission level needed and audit VIEWER-level access
  • Monitor Grafana hosts for unexpected child processes spawned by the Grafana service

Detection

  • Alert on Grafana service processes spawning shell or unexpected binaries such as duckdb
  • Review Grafana audit and access logs for SQL Expressions queries containing shell metacharacters or file paths
  • Hunt for anomalous file reads or outbound connections originating from the Grafana host
  • Check for duckdb presence in Grafana's runtime $PATH as an exposure indicator

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9264 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2020-27846Grafana vulnerabilityA signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th…EPSS 4.9%9.8CVE-2018-15727Grafana authentication bypass via forged remember-me cookieGrafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" c…EPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2024-9264), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.