Vulnerability record · CVE-2024-9264 · published 18 October 2024
CVE-2024-9264: Grafana SQL Expressions feature allows command injection and file read
Grafana · Grafana
Grafana's experimental SQL Expressions feature evaluates duckdb queries containing user input without sufficient sanitization, enabling command injection and local file inclusion. Any authenticated user with VIEWER permission or higher can trigger it, making it a serious risk for multi-tenant or broadly accessible Grafana instances. The duckdb binary must be present in Grafana's $PATH, and it is not installed by default.
Description
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityCritical CVSS 9.4 and near-top EPSS score, but exploitation requires authentication and the non-default duckdb binary, lowering real-world reachability.
What it is
Grafana's experimental SQL Expressions feature evaluates duckdb queries containing user input without sufficient sanitization, enabling command injection and local file inclusion. Any authenticated user with VIEWER permission or higher can trigger it, making it a serious risk for multi-tenant or broadly accessible Grafana instances. The duckdb binary must be present in Grafana's $PATH, and it is not installed by default.
Impact
An attacker gains arbitrary command execution on the Grafana host and can read local files, with high confidentiality, integrity and availability impact across the vulnerable component and connected systems. This can lead to full host compromise and access to Grafana data sources and credentials.
Attack surface
Reached over the network through the SQL Expressions feature by an authenticated user holding VIEWER or higher permission; no user interaction is required. The attack only works if the duckdb binary is installed and available in Grafana's $PATH.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged, but EPSS is very high at 0.94864 (99.856th percentile), indicating strong predicted exploitation activity. No ransomware group usage is documented.
What to do
- Upgrade Grafana to a version that fixes CVE-2024-9264 per the vendor advisory
- Disable the experimental SQL Expressions feature if it is not required
- Remove the duckdb binary from Grafana's $PATH or avoid installing it where SQL Expressions is enabled
- Restrict Grafana accounts to the minimum permission level needed and audit VIEWER-level access
- Monitor Grafana hosts for unexpected child processes spawned by the Grafana service
Detection
- Alert on Grafana service processes spawning shell or unexpected binaries such as duckdb
- Review Grafana audit and access logs for SQL Expressions queries containing shell metacharacters or file paths
- Hunt for anomalous file reads or outbound connections originating from the Grafana host
- Check for duckdb presence in Grafana's runtime $PATH as an exposure indicator
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-9264 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-9264), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.