CVE-2026-17033

CVE-2026-17033 CVE Record

An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session. Grafana renders alert.generatorURL directly as the Alert Details See source LinkButton href without URL-scheme sanitization or a safe-protocol allowlist. The click interceptor's :// heuristic can be bypassed by placing :// inside a JavaScript comment. When a user with read access clicks See source, the browser executes attacker-controlled JavaScript in the Grafana origin with the clicking user's permissions.


We have discovered 602 live websites that are affected by CVE-2026-17033.

Run a Free Instant Scan




Affected Software

Product  Grafana
Category Analytics
Vulnerable Domains602 live websites (100% of Grafana install base)
Vulnerable Versions
  • from 0 through 12.3.11
  • from 12.4 through 12.4.9
  • from 13 through 13.0.7
Vulnerable Versions Count76 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 24, 2026
  • Updated - Aug 27, 2026

Credits

  • nlgbao1340 (finder)

Website Distribution by Country

Number of websites using CVE-2026-17033
United States277 websites



Germany99 websites
France46 websites
Russia25 websites
Singapore18 websites
Switzerland15 websites
China14 websites
Netherlands11 websites
Czech Republic9 websites

Website Distribution by TLD

Number of websites using CVE-2026-17033
.com159 websites
.io94 websites
.net54 websites
.org44 websites
.de40 websites
.ru21 websites
.ch17 websites
.fr12 websites
.eu11 websites
.it8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-17033

Top websites that are affected by CVE-2026-17033. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*******.io France**,***
**.*****************.com Germany**,***
********.kz Kazakhstan***,***
***.********.****.io United States***,***
********.info France***,***
********.com United States***,***
**********.********.****.io United States***,***
***.********.****.io United States*,***,***
****.********.org United States*,***,***
*******.***.ch Switzerland*,***,***
See full domain list

FAQ

CVE-2026-17033 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Grafana
A total of 602 websites have been identified as vulnerable to CVE-2026-17033, based on global website indexing conducted by WebTechSurvey.
The Grafana is affected by the CVE-2026-17033 vulnerability.
Grafana versions up to and including 13.0.7 are vulnerable to CVE-2026-17033.