← Back to CVE List
CVE-2026-76154NVD
Description
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
CVSS Base Metrics
CVSS v3 (3.1)
HIGH 7.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Weaknesses (CWE)
CWE-79 - CWE-79
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| Grafana Grafana OSS | 12.3.0, 12.4.0 - <= 12.4.10, 13.0.0 - <= 13.0.8, 13.1.0 - <= 13.1.5, 13.2.0 - <= 13.2.1 | N/A |
| Grafana Grafana Enterprise | 12.3.0, 12.4.0 - <= 12.4.10, 13.0.0 - <= 13.0.8, 13.1.0 - <= 13.1.5, 13.2.0 - <= 13.2.1 | N/A |