{"id":"CVE-2026-76154","title":"A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…","summary":"A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-79"],"vendor":"Grafana","product":"Grafana OSS","affected":["oss 12.3.0","oss >= 12.4.0 <= 12.4.10","oss >= 13.0.0 <= 13.0.8","oss >= 13.1.0 <= 13.1.5","oss >= 13.2.0 <= 13.2.1","enterprise 12.3.0","enterprise >= 12.4.0 <= 12.4.10","enterprise >= 13.0.0 <= 13.0.8","enterprise >= 13.1.0 <= 13.1.5","enterprise >= 13.2.0 <= 13.2.1"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:34:36.657","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76154","references":[{"url":"https://grafana.com/security/security-advisories/cve-2026-76154","label":"security@grafana.com"}],"tags":["nvd","cve.org"],"epss":0.00393,"epssPercentile":0.33174,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T17:33:54.472083Z"},"ingestedAt":"2026-09-17T21:29:16.985Z","slug":"CVE-2026-76154","body":"## Overview\n\nA stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}