CVE-2026-14199

Summary

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

Affected Software

VendorProductVersion RangeStatus
GrafanaGrafana Enterprise11.0.0 <= 11.6.17affected
GrafanaGrafana Enterprise12.0.0 <= 12.2.11affected
GrafanaGrafana Enterprise12.3.0 <= 12.3.11affected
GrafanaGrafana Enterprise12.4.0 <= 12.4.9affected
GrafanaGrafana Enterprise13.0.0 <= 13.0.7affected
GrafanaGrafana Enterprise13.1.0 <= 13.1.4affected
GrafanaGrafana Enterprise13.2.0 <= 13.2.0affected
GrafanaGrafana OSS11.0.0 <= 11.6.17affected
GrafanaGrafana OSS12.0.0 <= 12.2.11affected
GrafanaGrafana OSS12.3.0 <= 12.3.11affected
GrafanaGrafana OSS12.4.0 <= 12.4.9affected
GrafanaGrafana OSS13.0.0 <= 13.0.7affected
GrafanaGrafana OSS13.1.0 <= 13.1.4affected
GrafanaGrafana OSS13.2.0 <= 13.2.0affected

Weaknesses

  • CWE-290: CWE-290
  • CWE-1023: CWE-1023
  • CWE-863: CWE-863

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References