Stored Cross-Site Scripting Vulnerability in Grafana Geomap Panel
CVE-2026-76154

7.3HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
17 September 2026

What is CVE-2026-76154?

A stored cross-site scripting vulnerability exists within the Geomap panel's integration with MapLibre. This issue permits users in the Editor role to craft malicious style configurations that could execute arbitrary JavaScript in the session of another user. This vulnerability poses a significant risk, as it could lead to unauthorized actions or data exposure by escalating privileges to Org Admin.

Affected Version(s)

Grafana Enterprise 12.3.0

Grafana Enterprise 12.4.0 <= 12.4.10

Grafana Enterprise 13.0.0 <= 13.0.8

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.