Description
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 22 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host. | |
| Title | Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-06-22T13:20:29.440Z
Reserved: 2026-02-27T07:16:12.218Z
Link: CVE-2026-28381
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.