Junglewise Threat Intelligence

CVE-2026-76154: Grafana OSS stored XSS in Geomap MapLibre base layer

CVE-2026-76154 · Severity: high · CVSS 7.3 · Published 2026-09-17

Vendors: Grafana.

Executive brief

Grafana OSS is an open-source observability and visualization platform used to display operational metrics and logs. A vulnerability in the Geomap panel allows an Editor-role user to inject malicious code that executes in other users' browsers when they view the affected panel, potentially allowing an attacker to escalate privileges to admin level.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Geomap panel's MapLibre base layer configuration. An attacker with Editor role can host a malicious MapLibre style configuration and reference it in the Geomap panel settings. When other users view the affected panel, the injected JavaScript executes in their session with their privileges. The vulnerability requires user interaction (viewing the malicious panel) and stored persistence, enabling privilege escalation to Org Admin. Patches are available in versions 12.4.11+, 13.0.9+, 13.1.6+, and 13.2.2+.

Affected products

  • Grafana Grafana OSS <12.3.0, 12.3.0 to <12.4.11, >=13.0.0 <13.0.9, >=13.1.0 <13.1.6, >=13.2.0 <13.2.2

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched

References