CVE-2026-9029: Stored XSS in the Geomap panel tile-layer attribution
Published Jun 22, 2026
·Updated
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Affected Software
2 affected components
Grafana Labs Grafana Geomap panel
Grafana Grafana=12.4.0
Event History
Jun 22, 2026
CVE Published
via MITRE·01:18 PM
Data Sourced
via MITRE·01:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Jul 3, 58550
Event
via FIRST·04:54 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-9029?
The severity of CVE-2026-9029 is rated as high, with a CVSS score of 7.3.
2
What type of vulnerability is CVE-2026-9029?
CVE-2026-9029 is identified as a Stored Cross-Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-9029?
To mitigate CVE-2026-9029, update your Grafana Geomap panel to the latest version where the vulnerability has been patched.
4
What impact does CVE-2026-9029 have?
CVE-2026-9029 allows an attacker to execute arbitrary JavaScript in a user's browser, potentially leading to data theft or session hijacking.
5
Which software is affected by CVE-2026-9029?
CVE-2026-9029 affects the Grafana Labs Grafana Geomap panel.