Geomap MapLibre XSS
High
- Advisory ID:
- CVE-2026-76154
- Published:
- 2026-09-17
- Product:
- Grafana OSS
- CVSS Score:
- 7.3
- CVSS Vector:
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Fixed Versions:
- <12.3.0>=12.4.11 <13.0.0>=13.0.9 <13.1.0>=13.1.6 <13.2.0>=13.2.2
Summary
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.