Feed/CVE-2024-9264
CVE-2024-9264CRITICALCVSS 9.9

CVE-2024-9264

Published Oct 17, 2024·Updated Jun 17, 2026

NVD Description

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

Public Exploits & PoCs11 found

PoC: CVE-2024-9264

Exploit for Grafana arbitrary file-read (CVE-2024-9264)

2

PoC: CVE-2024-9264-RCE-Exploit

Grafana RCE exploit (CVE-2024-9264)

1

PoC: CVE-2024-9264-in-Grafana-11.x

Vulnerability Exploitation using tools Penetration Testing, Grafana, Docker, Kali Linux.

PoC: CVE-2024-9264

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

PoC: day05-grafana-sqlexpr-lab

Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)

PoC: grafana-CVE-2024-9264

Grafana image with DuckDB binary present vulnerable to exploit CVE-2024-9264

PoC: CVE-2024-9264

Authenticated RCE in Grafana (v11.0) via SQL Expressions - PoC Exploit

PoC: CVE-2024-9264

Grafana RCE

PoC: CVE-2024-9264

A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.

PoC: CVE-2024-9264

Exploit for Grafana arbitrary file-read (CVE-2024-9264)

PoC: File-Read-CVE-2024-9264

File Read Proof of Concept for CVE-2024-9264

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free