CVE-2026-9029: Grafana
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Affected products
- Grafana Grafana: version 12.4.0 only
Published 2026-06-22. Last modified 2026-07-10.