Geomap MapLibre XSS

High
Advisory ID:
CVE-2026-76154
Published:
2026-09-17
Product:
Grafana OSS
CVSS Score:
7.3
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Fixed Versions:
<12.3.0
>=12.4.11 <13.0.0
>=13.0.9 <13.1.0
>=13.1.6 <13.2.0
>=13.2.2

Summary

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.