# REPRO-2026-00125: Grafana SQL Expressions RCE ## Summary Status: published Severity: critical Type: security Confidence: Unknown ## Identifiers REPRO ID: REPRO-2026-00125 CVE: CVE-2026-27876 ## Package Name: grafana/grafana Ecosystem: github Affected: 11.6.0 Fixed: 11.6.14 ## Root Cause # RCA Report: CVE-2026-27876 Grafana SQL Expressions RCE ## Summary CVE-2026-27876 is a critical vulnerability in Grafana's SQL Expressions feature that allows authenticated users (Viewer+) to achieve arbitrary file write via malicious SQL queries using INTO clauses. The vulnerability exists because the SQL expression parser did not block INTO clauses, allowing attackers to write files to the filesystem. This can be chained with vulnerable Grafana Enterprise plugins (like Sqlyze driver