CVE-2026-76154
7.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Summary
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Grafana OSS | 12.3.0 | affected |
| Grafana | Grafana OSS | 12.4.0 <= 12.4.10 | affected |
| Grafana | Grafana OSS | 13.0.0 <= 13.0.8 | affected |
| Grafana | Grafana OSS | 13.1.0 <= 13.1.5 | affected |
| Grafana | Grafana OSS | 13.2.0 <= 13.2.1 | affected |
| Grafana | Grafana Enterprise | 12.3.0 | affected |
| Grafana | Grafana Enterprise | 12.4.0 <= 12.4.10 | affected |
| Grafana | Grafana Enterprise | 13.0.0 <= 13.0.8 | affected |
| Grafana | Grafana Enterprise | 13.1.0 <= 13.1.5 | affected |
| Grafana | Grafana Enterprise | 13.2.0 <= 13.2.1 | affected |
Weaknesses
- CWE-79: CWE-79
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.