CVE-2026-76154 PUBLISHED

CVE-2026-76154 CVE Record

Assigner: GRAFANA
Reserved: 19.08.2026 Published: 17.09.2026 Updated: 17.09.2026

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 7.3

Product Status

Vendor Grafana
Product Grafana OSS
Versions Default: unaffected
  • Version 12.3.0 is affected
  • affected from 12.4.0 to 12.4.10 (incl.)
  • affected from 13.0.0 to 13.0.8 (incl.)
  • affected from 13.1.0 to 13.1.5 (incl.)
  • affected from 13.2.0 to 13.2.1 (incl.)
Vendor Grafana
Product Grafana Enterprise
Versions Default: unaffected
  • Version 12.3.0 is affected
  • affected from 12.4.0 to 12.4.10 (incl.)
  • affected from 13.0.0 to 13.0.8 (incl.)
  • affected from 13.1.0 to 13.1.5 (incl.)
  • affected from 13.2.0 to 13.2.1 (incl.)

References

Problem Types

  • CWE-79 CWE