CVE-2026-33375: Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33375?
CVE-2026-33375 is classified as a critical severity vulnerability due to its potential to cause Out-Of-Memory (OOM) conditions.
How do I fix CVE-2026-33375?
To remediate CVE-2026-33375, it is recommended to update to the latest version of the Grafana MSSQL Data Source plugin that includes the security fix.
Who is affected by CVE-2026-33375?
CVE-2026-33375 affects users of the Grafana MSSQL Data Source plugin, specifically allowing low-privileged users to exploit the vulnerability.
What kind of attack does CVE-2026-33375 enable?
CVE-2026-33375 enables a denial-of-service attack by causing memory exhaustion on the host container.
Can CVE-2026-33375 be exploited remotely?
Yes, CVE-2026-33375 can potentially be exploited remotely by low-privileged users who have access to the Grafana environment.