CVE-2026-9029
Stored XSS in the Geomap panel tile-layer attribution
CVSS Score
7.3
EPSS Score
0.3%
EPSS Percentile
17th
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
| CWE | CWE-79 |
| Vendor | grafana |
| Product | grafana oss |
| Ecosystems | |
| Industries | Technology |
| Published | Jun 22, 2026 |
| Last Updated | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for grafana grafana oss
Be the first to know when new high vulnerabilities affecting grafana grafana oss are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Grafana / Grafana OSS
12.4.0 โค 12.4.3 13.0.0 โค 13.0.1
References
Credits
trailerb18 (Researcher)