CVE-2026-9029: Grafana

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

Affected products

  • Grafana Grafana: version 12.4.0 only

Published 2026-06-22. Last modified 2026-07-10.