Cross-Site Scripting Vulnerability in Grafana Geomap MapLibre
Grafana OSS versions 12.x and 13.x contain a cross-site scripting (XSS) vulnerability (CVE-2026-76154) in the Geomap MapLibre component that could allow attackers to execute malicious scripts in a user's session.
CVE search metadata
CVE search record: CVE-2026-76154. Severity: high. CVSS: 7.3. KEV: no. Product: Grafana OSS (12.3.0 to 12.4.10, 13.0.0 to 13.0.8, 13.1.0 to 13.1.5, 13.2.0 to 13.2.1). Brief: Cross-Site Scripting Vulnerability in Grafana Geomap MapLibre. Brief link: https://feed.craftedsignal.io/briefs/2026-09-grafana-xss/
On September 17, 2026, the Cyber Centre reported multiple vulnerabilities affecting various versions of Grafana OSS. The most critical issue identified is CVE-2026-76154, a cross-site scripting (XSS) vulnerability located within the Geomap MapLibre component. This vulnerability poses a significant risk to organizations, as a successful exploit allows an unauthorized party to execute malicious JavaScript within the context of an authenticated user's session. Depending on the user's role and permissions, this could lead to sensitive data theft, session hijacking, or the performance of unauthorized administrative actions within the Grafana instance. Affected versions include 12.3.0 through 12.4.10, 13.0.0 through 13.0.8, 13.1.0 through 13.1.5, and 13.2.0 through 13.2.1. Given the potential impact on data integrity and user account security, administrators should prioritize updating to the latest secure version of Grafana.
Impact
Successful exploitation of CVE-2026-76154 enables attackers to bypass intended security controls by executing arbitrary client-side code. This can lead to full account takeover for authenticated users, unauthorized access to dashboard data, or the redirection of users to malicious infrastructure. The vulnerability impacts any organization relying on Grafana for operational monitoring and visualization, potentially exposing internal infrastructure data if the attacker gains administrative control.
Recommendation
Prioritize patching all affected Grafana OSS instances to the latest available version provided by Grafana. Review all active user sessions for suspicious activity and consider implementing stricter Content Security Policy (CSP) headers to mitigate potential XSS impacts. Monitor web access logs for unusual requests targeting the Geomap or MapLibre components as potential indicators of probing or exploitation attempts.
Immediate actions
Upgrade all affected Grafana OSS instances to the latest secure version.
Mitigations
Upgrade Grafana OSS to the latest version per vendor security advisory.
CVE-2026-76154