XSS Vulnerability in Grafana Geomap Panel
CVE-2026-9029
7.3HIGH
What is CVE-2026-9029?
A Cross-Site Scripting (XSS) vulnerability exists in the Geomap panel of Grafana that stems from a flaw in the sanitization process for template strings. This vulnerability arises due to the improper ordering of operations – where raw template strings are sanitized before variable substitution, allowing malicious payloads to be injected. An Editor can exploit this flaw by setting a textbox variable's default value to an XSS payload, which will execute for every user who accesses the dashboard. This security oversight bypasses previous mitigations put in place under CVE-2023-0507.
Affected Version(s)
Grafana OSS OnPrem 12.4.0