Security
Loading…

CVE-2026-33387

MEDIUMCVSS 4.6
Description

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.

Timeline
Published:September 8th, 2026 2:17 PM
Last modified:September 8th, 2026 7:12 PM
CVSS Scoring

CVSS v3: 4.6 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute