The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-28381 represents a critical authorization bypass vulnerability in Grafana's Snowflake datasource integration. By exploiting GET/PUT command functionality, any user with query execution privileges can read and write arbitrary files between the Grafana server and connected Snowflake instances, bypassing intended access controls. This affects organizations using Grafana to visualize Snowflake data, potentially exposing sensitive datasets, configuration files, and enabling lateral movement through the data pipeline. With a CVSS score of 9.6, the vulnerability poses severe risk to data confidentiality, integrity, and availability across dependent systems.
While this vulnerability currently maps to zero Casky skills due to its specificity to Grafana-Snowflake integration, practitioners using Casky's Claude-powered analysis would benefit from detection patterns aligned with T1020 (Automated Exfiltration), T1048 (Exfiltration Over Alternative Protocol), and T1570 (Lateral Tool Transfer). Extended reasoning analysis would identify suspicious patterns such as: unexpected GET/PUT command execution in Snowflake query logs, large data transfers between Grafana and Snowflake outside normal analytical workflows, access to configuration or system files through datasource queries, and privilege escalation attempts leveraging file-write capabilities. Security teams should monitor for these behavioral indicators while awaiting skill coverage expansion specific to Grafana datasource vulnerabilities.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-28381. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation