CVE-2026-33387
MEDIUMCVSS 4.6Description
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.
Timeline
Published:September 8th, 2026 2:17 PM
Last modified:September 8th, 2026 7:12 PM
CVSS Scoring
CVSS v3: 4.6 (MEDIUM)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports
Source: NIST NVD · Data may lag official sources by up to one minute