Medium severity6.8OSV Advisory· Published Jul 10, 2026· Updated Jul 13, 2026
CVE-2026-8595
CVE-2026-8595
Description
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
Affected products
6- osv-coords3 versionspkg:bitnami/grafanapkg:rpm/opensuse/grafana&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2016.0
>= 12.4.0, < 12.4.4+ 2 more
- (no CPE)range: >= 12.4.0, < 12.4.4
- (no CPE)range: < 12.4.5-3.1
- (no CPE)range: < 12.4.5-bp160.2.1
Patches
Vulnerability mechanics
References
1- grafana.com/security/security-advisories/cve-2026-8595nvdVendor Advisory
News mentions
1- Grafana: Three Moderate Vulnerabilities Including Stored XSS and DoS Disclosed TogetherVypr Intelligence · Jul 10, 2026