AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-8595

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

A vulnerability exists that allows users with Editor permissions to create a dashboard containing a malicious field name in the TableNG panel, leading to stored cross-site scripting (XSS) attacks. This can result in the execution of arbitrary scripts in the browsers of any users who view the compromised dashboard, potentially exposing sensitive information or facilitating further attacks. Organizations utilizing this dashboard feature should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-8595
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%

Original NVD Description

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

Related CVEs

Other vulnerabilities affecting the same vendor(s)