CVE-2026-33387

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
08/09/2026
Last modified:
08/09/2026

Description

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.

References to Advisories, Solutions, and Tools