Grafana LabsCVE-2026-14199
Grafana: authentication bypass
High7.1CVE-2026-14199 · Published Sep 2, 2026 · updated Sep 15, 2026
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana Enterprise Product | >= 11.0.0, <= 11.6.17 | No fix yet |
| >= 12.0.0, <= 12.2.11 | No fix yet | |
| >= 12.3.0, <= 12.3.11 | No fix yet | |
| >= 12.4.0, <= 12.4.9 | No fix yet | |
| Grafana OSS Product | >= 11.0.0, <= 11.6.17 | No fix yet |
| >= 12.0.0, <= 12.2.11 | No fix yet | |
| >= 12.3.0, <= 12.3.11 | No fix yet | |
| >= 12.4.0, <= 12.4.9 | No fix yet |
Details and references
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Grafana OSS: denial of service | Medium6.5 | No fix yet |
| Sep 2 | Grafana Enterprise: capture-replay | Medium6.8 | No fix yet |
| Aug 27 | Grafana Labs Alloy: exposed files | High7.7 | No fix yet |
| Aug 27 | Grafana Labs Clickhouse Datasource: cleartext transmission | Medium6.1 | No fix yet |
| Aug 26 | Grafana: improper access control | Medium6.3 | OSS 12.4.8+2 more |
| Aug 24 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |