
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76154 is a stored cross-site scripting (XSS) vulnerability in Grafana's Geomap panel MapLibre base layer that allows a user with the Editor role to execute arbitrary JavaScript in another user's browser session by hosting a malicious style configuration, potentially enabling privilege escalation to Org Admin. It affects Grafana OSS and Grafana Enterprise versions 12.3.0, 12.4.0–12.4.10, 13.0.0–13.0.8, 13.1.0–13.1.5, and 13.2.0–13.2.1. The vulnerability was published on September 17, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Grafana Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The root cause is insufficient sanitization of user-supplied style configuration input in the Geomap panel's MapLibre base layer, which allows an Editor-role user to inject and persist malicious JavaScript. Exploitation requires the attacker to host a crafted MapLibre style configuration and have a victim user (such as an Org Admin) load the affected Geomap panel, triggering execution of the injected script in the victim's session. No public proof-of-concept code has been identified at this time (GitHub Advisory, Grafana Advisory).
Successful exploitation allows an attacker with Editor-level access to execute arbitrary JavaScript in the browser session of any user who views the compromised Geomap panel, including Org Admins. This can result in session token theft (high confidentiality impact), unauthorized configuration changes or data manipulation (high integrity impact), and privilege escalation from Editor to Org Admin — potentially granting full organizational control within the Grafana instance. Availability is not directly impacted (GitHub Advisory, Feedly).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated Editor-role account and social engineering to have a privileged user view the malicious dashboard panel (GitHub Advisory, Feedly).
/api/org/users) originating from admin sessions shortly after dashboard views.Grafana has released patched versions addressing this vulnerability: 12.4.11, 13.0.9, 13.1.6, and 13.2.2 (or later). Users should upgrade to the appropriate fixed release immediately. As interim mitigations, organizations should restrict Editor role permissions where possible, audit existing Geomap panel configurations for external or suspicious MapLibre style URLs, and review audit logs for unauthorized privilege escalations to Org Admin. Monitoring for suspicious dashboard configurations referencing external style sources is also recommended (Grafana Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."