<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Sqlexpression — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/sqlexpression/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 27 Mar 2026 15:16:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/sqlexpression/feed.xml" rel="self" type="application/rss+xml"/><item><title>Grafana Enterprise Plugin SQL Expression RCE via CVE-2026-27876</title><link>https://feed.craftedsignal.io/briefs/2026-03-grafana-rce/</link><pubDate>Fri, 27 Mar 2026 15:16:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-grafana-rce/</guid><description>A chained attack leveraging SQL Expressions and a Grafana Enterprise plugin, tracked as CVE-2026-27876, can lead to remote arbitrary code execution on vulnerable Grafana instances with the sqlExpressions feature enabled.</description><content:encoded><![CDATA[<p>CVE-2026-27876 describes a critical vulnerability in Grafana that allows for remote arbitrary code execution (RCE). The vulnerability stems from a chained attack involving SQL Expressions and a Grafana Enterprise plugin. Successful exploitation requires the <code>sqlExpressions</code> feature toggle to be enabled on the Grafana instance. Grafana Labs strongly recommends that all users update their Grafana instances to the latest version to mitigate the risk of exploitation, even if the <code>sqlExpressions</code>…</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>grafana</category><category>rce</category><category>sqlexpression</category></item></channel></rss>