AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-9264

CRITICAL · CVSS 9.9 EPSS 94.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-10-18 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.9. Its EPSS score suggests a 94.6% probability of exploitation in the next 30 days.

CVE
CVE-2024-9264
Severity
CRITICAL
CVSS
9.9
EPSS
94.64%

Original NVD Description

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)