Vulnerability Details CVE-2026-9029
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 16.4%
CVSS Severity
CVSS v3 Score 7.3
Products affected by CVE-2026-9029
-
cpe:2.3:a:grafana:grafana:12.4.0