CVE-2026-8595: Stored XSS in the table panel (TableNG)
Published Jul 10, 2026
·Updated
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
Affected Software
3 affected components
TableNG
Grafana Grafana>=12.4.0<12.4.4
Grafana Grafana>=13.0.0<13.0.2
Event History
Jul 10, 2026
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-8595?
The severity of CVE-2026-8595 is classified as medium with a score of 6.8.
2
What type of vulnerability is CVE-2026-8595?
CVE-2026-8595 is a stored cross-site scripting (XSS) vulnerability.
3
Who can exploit CVE-2026-8595?
A user with Editor permissions can exploit CVE-2026-8595 by crafting a malicious dashboard.
4
What impact does CVE-2026-8595 have on users?
CVE-2026-8595 allows an attacker to execute scripts in the browser of any user who views the compromised dashboard.
5
How do I fix CVE-2026-8595?
To fix CVE-2026-8595, users should ensure that they are using the latest version of the software with security patches that address this vulnerability.