Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76154
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-76154 is a stored cross-site scripting (XSS) vulnerability in Grafana's Geomap panel MapLibre base layer that allows a user with the Editor role to execute arbitrary JavaScript in another user's browser session by hosting a malicious style configuration, potentially enabling privilege escalation to Org Admin. It affects Grafana OSS and Grafana Enterprise versions 12.3.0, 12.4.0–12.4.10, 13.0.0–13.0.8, 13.1.0–13.1.5, and 13.2.0–13.2.1. The vulnerability was published on September 17, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Grafana Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The root cause is insufficient sanitization of user-supplied style configuration input in the Geomap panel's MapLibre base layer, which allows an Editor-role user to inject and persist malicious JavaScript. Exploitation requires the attacker to host a crafted MapLibre style configuration and have a victim user (such as an Org Admin) load the affected Geomap panel, triggering execution of the injected script in the victim's session. No public proof-of-concept code has been identified at this time (GitHub Advisory, Grafana Advisory).

Impact

Successful exploitation allows an attacker with Editor-level access to execute arbitrary JavaScript in the browser session of any user who views the compromised Geomap panel, including Org Admins. This can result in session token theft (high confidentiality impact), unauthorized configuration changes or data manipulation (high integrity impact), and privilege escalation from Editor to Org Admin — potentially granting full organizational control within the Grafana instance. Availability is not directly impacted (GitHub Advisory, Feedly).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated Editor-role account and social engineering to have a privileged user view the malicious dashboard panel (GitHub Advisory, Feedly).

Exploitation steps

  1. Gain Editor Access: Obtain or compromise a Grafana account with at least the Editor role on the target Grafana instance.
  2. Host Malicious Style Configuration: Set up an externally accessible server hosting a crafted MapLibre style JSON file containing a malicious JavaScript payload (e.g., a script that exfiltrates the victim's session cookie or performs API calls on their behalf).
  3. Configure Geomap Panel: In a Grafana dashboard, add or edit a Geomap panel and configure the MapLibre base layer to reference the attacker-controlled malicious style configuration URL.
  4. Save and Share Dashboard: Save the dashboard containing the malicious Geomap panel. Use social engineering or normal workflow to have a higher-privileged user (e.g., Org Admin) open or view the dashboard.
  5. Trigger XSS Execution: When the victim loads the dashboard, the Geomap panel fetches and processes the malicious style configuration, executing the injected JavaScript in the victim's browser session.
  6. Escalate Privileges: Use the executed JavaScript to steal session tokens, perform authenticated API calls to promote the attacker's account to Org Admin, or exfiltrate sensitive data (GitHub Advisory, Grafana Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the Grafana server or user browsers to unexpected external domains serving JSON/style configuration files; unusual API calls to Grafana's user management endpoints (e.g., /api/org/users) originating from admin sessions shortly after dashboard views.
  • Logs: Grafana audit logs showing Org Admin role assignments or permission changes not initiated by a known administrator; access logs showing requests to Geomap panel dashboards followed by privilege escalation events.
  • Application Behavior: Unexpected changes to Grafana organization user roles (especially Editor-to-Admin promotions); dashboard configurations referencing external, non-organizational MapLibre style URLs in Geomap panels.
  • Browser/Session: Session tokens used from multiple IP addresses in a short timeframe; API tokens created or modified without corresponding user-initiated actions (Grafana Advisory, GitHub Advisory).

Mitigation and workarounds

Grafana has released patched versions addressing this vulnerability: 12.4.11, 13.0.9, 13.1.6, and 13.2.2 (or later). Users should upgrade to the appropriate fixed release immediately. As interim mitigations, organizations should restrict Editor role permissions where possible, audit existing Geomap panel configurations for external or suspicious MapLibre style URLs, and review audit logs for unauthorized privilege escalations to Org Admin. Monitoring for suspicious dashboard configurations referencing external style sources is also recommended (Grafana Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15815HIGH8.8
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesSep 17, 2026
CVE-2026-92596HIGH8.7
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 16, 2026
CVE-2026-76154HIGH7.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoNoSep 17, 2026
CVE-2026-81872MEDIUM6.3
  • Grafana logoGrafana
  • opentelemetry-collector.src
NoNoSep 16, 2026
CVE-2026-81871MEDIUM6.3
  • Grafana logoGrafana
  • amazon-cloudwatch-agent
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management