CVE-2026-9029High· 7.3▾ TwilightA user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
grafana = 12.4.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/grafana/grafana >= 2.0.0-beta1, < 12.4.4github.com/grafana/grafana >= 13.0.0, < 13.0.2github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059Patched in:
github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42127High· 7.5The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads
CVE-2026-10601Medium· 5.4A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints
CVE-2026-42129High· 7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
CVE-2026-14199High· 7.1Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected
CVE-2025-41118Critical· 9.1Pyroscope is an open-source continuous profiling database
CVE-2026-21728High· 7.5Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g