CVE-2026-0712: XSS
Published Jan 15, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Grafana Grafana OSS>=11.5.0
Remediation
Information
Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
Event History
Jan 15, 2026
CVE Published
via MITRE·01:10 PM
Rejected
via MITRE·01:10 PM
Data Sourced
via NVD·01:16 PM
Description
Jan 22, 2026
Rejected
via MITRE·05:02 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-0712?
CVE-2026-0712 is classified as a critical vulnerability due to its potential to enable XSS attacks through open redirects.
2
How do I fix CVE-2026-0712?
To mitigate CVE-2026-0712, update Grafana OSS to versions 12.0.2+security-01 or 11.6.3+security-01.
3
What versions of Grafana are affected by CVE-2026-0712?
CVE-2026-0712 affects Grafana OSS versions starting from 11.5.0.
4
Can CVE-2026-0712 be exploited through other vulnerabilities?
Yes, CVE-2026-0712 can be chained with path traversal vulnerabilities to facilitate XSS attacks.
5
Is there a workaround for CVE-2026-0712 if I cannot update Grafana?
If updating is not feasible, implement strict input validation and avoid using user-controlled redirects to mitigate CVE-2026-0712.