Grafana LabsCVE-2026-12704
Grafana Enterprise: capture-replay
Medium6.8CVE-2026-12704 · Published Sep 2, 2026 · updated Sep 3, 2026
When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana Enterprise Product | >= 11.6.0, <= 11.6.17 | No fix yet |
| >= 12.2.0, <= 12.2.11 | No fix yet | |
| >= 12.3.0, <= 12.3.11 | No fix yet | |
| >= 12.4.0, <= 12.4.10 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-294
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Grafana OSS: denial of service | Medium6.5 | No fix yet |
| Sep 2 | Grafana: authentication bypass | High7.1 | No fix yet |
| Aug 27 | Grafana Labs Alloy: exposed files | High7.7 | No fix yet |
| Aug 27 | Grafana Labs Clickhouse Datasource: cleartext transmission | Medium6.1 | No fix yet |
| Aug 26 | Grafana: improper access control | Medium6.3 | OSS 12.4.8+2 more |
| Aug 24 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |