CVE-2026-33387: Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dashboards/Guardian/CMCto a version that resolves this vulnerability.Fixed in 26.3.0 or later
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with the required dashboard privileges can create a dashboard containing a malicious payload. A victim may also be exposed by importing a malicious dashboard supplied through social engineering.
When does the malicious payload execute?
The payload executes in the victim's browser context when the victim views or imports the malicious dashboard. User interaction is therefore required from the victim.
What could an attacker do after successful exploitation?
The attacker can modify application data or disrupt application availability through code executing in the victim's browser context.
Which versions are affected?
Guardian/CMC versions before 26.3.0 are affected.