A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.
References
| Link | Resource |
|---|---|
| https://security.nozominetworks.com/NN-2026:16-01 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 14:17
Updated : 2026-09-08 19:12
NVD link : CVE-2026-33387
Mitre link : CVE-2026-33387
CVE.ORG link : CVE-2026-33387
JSON object : View
Products Affected
No product.
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
