XSS Vulnerability in Grafana Geomap Panel
CVE-2026-9029

7.3HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
22 June 2026

What is CVE-2026-9029?

A Cross-Site Scripting (XSS) vulnerability exists in the Geomap panel of Grafana that stems from a flaw in the sanitization process for template strings. This vulnerability arises due to the improper ordering of operations – where raw template strings are sanitized before variable substitution, allowing malicious payloads to be injected. An Editor can exploit this flaw by setting a textbox variable's default value to an XSS payload, which will execute for every user who accesses the dashboard. This security oversight bypasses previous mitigations put in place under CVE-2023-0507.

Affected Version(s)

Grafana OSS OnPrem 12.4.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

trailerb18 (Researcher)
.