SAML Vulnerability in Grafana Enterprise from Grafana Labs
CVE-2026-12704

6.8MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
2 September 2026

What is CVE-2026-12704?

A vulnerability exists in Grafana Enterprise when SAML IdP-initiated login is enabled, where the SAML library fails to validate the InResponseTo field for all SAML responses. This flaw compromises the anti-replay protection and enables an attacker with access to a valid signed SAML assertion to replay it, thus impersonating the victim user in an active session. The vulnerability specifically affects instances where the allow_idp_initiated SAML setting is enabled, which is not turned on by default, meaning that most Grafana installations are safeguarded from this risk.

Affected Version(s)

Grafana Enterprise 11.6.0 <= 11.6.17

Grafana Enterprise 12.2.0 <= 12.2.11

Grafana Enterprise 12.3.0 <= 12.3.11

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.