CVE-2026-76154: CVE Record
Published Sep 17, 2026
·Updated
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
Affected Software
1 affected component
Geomap panel
Event History
Sep 17, 2026
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and attacker-controlled content are required for exploitation?
The attacker needs the Editor role and must host a malicious style configuration for the MapLibre base layer in the Geomap panel.
2
What is the likely impact if a victim loads the malicious content?
The attacker can execute arbitrary JavaScript in another user's session. This can enable privilege escalation to Org Admin.