CVE-2026-9029
published 2026-06-22CVE-2026-9029: A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.25%
16.7th percentile
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | 3scale-operator-bundle | — | — |
| grafana | grafana | — | — |
| grafana | grafana_oss | 12.4.0 – 12.4.3 | — |
| grafana | grafana_oss | 13.0.0 – 13.0.1 | — |
| rhceph | grafana-rhel10 | — | — |
| rhceph | grafana-rhel9 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug.
ghsa_unreviewed·2026-06-22·CVSS 5.4
CVE-2026-9029 [MEDIUM] The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug.
The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix
VulDB
Grafana OSS 12.4.0 Template String sanitizeTextPanelContent cross site scripting
vuldb·2026-06-22·CVSS 7.3
CVE-2026-9029 [HIGH] Grafana OSS 12.4.0 Template String sanitizeTextPanelContent cross site scripting
A vulnerability has been found in Grafana OSS 12.4.0 and classified as problematic. The affected element is the function sanitizeTextPanelContent of the component Template String Handler. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-9029. The attack is possible to be carried out remotely. No exploit exists.
Red Hat
grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel
vendor_redhat·2026-06-22·CVSS 5.4
CVE-2026-9029 [MEDIUM] CWE-79 grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel
grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
A flaw was found in the Grafana geomap panel's XYZ tile layer. An attacker with editor privileges can exploit a sanitize-then-interpolate ordering bug by setting a textbox variable's default value to a Cross-Site Scripting (XSS) payload. This payload executes for every user who opens the dashboard, potentially leading to arbitrary code execution and information disclosure.
Statement: An authenticated attacker with Editor
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9029 grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel [fedora-all]
bugzilla·2026-07-22·CVSS 5.4
CVE-2026-9029 [MEDIUM] CVE-2026-9029 grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel [fedora-all]
CVE-2026-9029 grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard
Bugzilla
CVE-2026-9029 grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel
bugzilla·2026-06-22·CVSS 5.4
CVE-2026-9029 [MEDIUM] CVE-2026-9029 grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel
CVE-2026-9029 grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel
The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix
2026-06-22
Published