VYPR
High severity7.3NVD Advisory· Published Jun 22, 2026· Updated Jul 10, 2026

CVE-2026-9029

CVE-2026-9029

Description

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.