Cross-site scripting in Grafana - CVE-2026-76154
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's session.
The vulnerability exists due to stored cross-site scripting in the Geomap panel's MapLibre base layer when a victim views a malicious hosted style configuration. A remote user can host a malicious style configuration to execute arbitrary JavaScript in another user's session.
Successful exploitation can enable escalation to the Org Admin role.