Executive brief
Grafana OSS is an open-source observability and visualization platform used to display operational metrics and logs. A vulnerability in the Geomap panel allows an Editor-role user to inject malicious code that executes in other users' browsers when they view the affected panel, potentially allowing an attacker to escalate privileges to admin level.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Geomap panel's MapLibre base layer configuration. An attacker with Editor role can host a malicious MapLibre style configuration and reference it in the Geomap panel settings. When other users view the affected panel, the injected JavaScript executes in their session with their privileges. The vulnerability requires user interaction (viewing the malicious panel) and stored persistence, enabling privilege escalation to Org Admin. Patches are available in versions 12.4.11+, 13.0.9+, 13.1.6+, and 13.2.2+.
Affected products
- Grafana Grafana OSS <12.3.0, 12.3.0 to <12.4.11, >=13.0.0 <13.0.9, >=13.1.0 <13.1.6, >=13.2.0 <13.2.2
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched