CVE-2026-22638: XSS
Published Jan 15, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Grafana Labs Grafana
Remediation
Information
Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
Event History
Jan 15, 2026
CVE Published
via MITRE·01:11 PM
Rejected
via MITRE·01:11 PM
Data Sourced
via NVD·02:16 PM
Description
Jan 22, 2026
Rejected
via MITRE·05:04 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-22638?
CVE-2026-22638 has been classified as a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2026-22638?
To fix CVE-2026-22638, update your Grafana installation to the latest version that addresses this vulnerability.
3
What are the possible impacts of CVE-2026-22638?
CVE-2026-22638 may allow attackers to redirect users and execute arbitrary JavaScript, potentially compromising user data.
4
Is CVE-2026-22638 exploitable without editor permissions?
Yes, CVE-2026-22638 can be exploited without requiring editor permissions, making it particularly dangerous.
5
Which versions of Grafana are affected by CVE-2026-22638?
CVE-2026-22638 affects multiple versions of Grafana, so all users should ensure they are using a patched version.