Crimson7 published a full proof-of-concept for CVE-2026-27876, a critical vulnerability in Grafana's SQL Expressions feature that chains arbitrary file write to remote code execution.
Public source
Publisher name
Public post
CVE-2026-27876: From SQL Expression to Root Shell in Grafana (CVSS 9.1) A full proof-of-concept for CVE-2026-27876 a critical vulnerability in Grafana's SQL Expressions…
Company
Crimson7
Translate adversary research into operational defence
- Industry
- Computer and Network Security
- Location
- Zaventem, BE
- Company size
- 11–50 employees
About Crimson7
Crimson7 empowers organizations to find and fix their security weaknesses before attackers do, combining purpose-built platforms with expert-led managed services. Headquartered in Belgium and operating across BeNeLux, the UK, Switzerland, and Italy, we help security teams move from reactive defense to continuous, proactive validation of their real-world attack surface.
See moreLatest activity
Latest activity from Crimson7
3 signals
Presence & Recognition
Crimson7 is attending Cybersec Netherlands in Jaarbeurs Utrecht on Wednesday 9 September and Thursday 10 September.
Products & Services
Crimson7 launched Ph1shy v2.0.0 on BreachForums in June at $500, featuring WebSocket updates, custom templates, multi-server, multi-user, JavaScript execution in the victim's browser, and a hosted backend with mutual TLS authentication.
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
Graylog, Inc.
Graylog, Inc. reported that attackers are actively exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component editor to steal cloud secrets.
Products & Services
Huntress
Huntress produced a proof of concept (PoC) of a new vulnerability chain CVE-2026-86206 and CVE-2026-86207 in N-central.
Products & Services
Northwave Cyber Security
Northwave Cyber Security discovered a critical security vulnerability in N-able N-central, an IT management platform.
Products & Services
Horizon3.ai
Horizon3.ai disclosed the technical details of CVE-2026-9586, a SQLi-to-RCE vulnerability in Sangoma Switchvox reported in April 2026.
Products & Services
OffSec