High severity7.3NVD Advisory· Published Jun 22, 2026· Updated Jul 10, 2026
CVE-2026-9029
CVE-2026-9029
Description
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Affected products
2Patches
Vulnerability mechanics
References
1- grafana.com/security/security-advisories/cve-2026-9029nvdBroken Link
News mentions
0No linked articles in our index yet.