Skip to content
Grafana LabsCVE-2026-14199

Grafana: authentication bypass

High7.1CVE-2026-14199 · Published Sep 2, 2026 · updated Sep 15, 2026

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana Enterprise
Product
>= 11.0.0, <= 11.6.17No fix yet
>= 12.0.0, <= 12.2.11No fix yet
>= 12.3.0, <= 12.3.11No fix yet
>= 12.4.0, <= 12.4.9No fix yet
Grafana OSS
Product
>= 11.0.0, <= 11.6.17No fix yet
>= 12.0.0, <= 12.2.11No fix yet
>= 12.3.0, <= 12.3.11No fix yet
>= 12.4.0, <= 12.4.9No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-290, CWE-863, CWE-1023

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana OSS: denial of service
Medium6.5Sep 2
Grafana Enterprise: capture-replay
Medium6.8Sep 2
Grafana Labs Alloy: exposed files
High7.7Aug 27
Grafana Labs Clickhouse Datasource: cleartext transmission
Medium6.1Aug 27
Grafana: improper access control
Medium6.3Aug 26
Grafana OSS: cross-site scripting
Medium6.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.