FlawAtlas
Search the atlas
CVE-2026-8595 Moderate

Stored XSS in the table panel (TableNG)

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

Exploit probability 0.2%
Published July 14, 2026
Required by Not available
Last source change July 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

Bitnami grafana
Unknown Unknown

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-8595

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

View original source
Open Source Vulnerabilities BIT-grafana-2026-8595

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

View original source

05 / REFERENCES

Further evidence