grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2026-9029 CVE-2026-9029
HIGH
Stored XSS in the Geomap panel tile-layer attribution
Record summary
CVE-2026-9029 has a selected CVSS score of 7.3 (high).
Description
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Grafana OSSBrowse Grafana / Grafana OSSDefault status: unaffected | CVE List | 12.4.0 to ≤ 12.4.3 | affected |
| 13.0.0 to ≤ 13.0.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-9029