SAML Vulnerability in Grafana Enterprise from Grafana Labs
CVE-2026-12704
6.8MEDIUM
What is CVE-2026-12704?
A vulnerability exists in Grafana Enterprise when SAML IdP-initiated login is enabled, where the SAML library fails to validate the InResponseTo field for all SAML responses. This flaw compromises the anti-replay protection and enables an attacker with access to a valid signed SAML assertion to replay it, thus impersonating the victim user in an active session. The vulnerability specifically affects instances where the allow_idp_initiated SAML setting is enabled, which is not turned on by default, meaning that most Grafana installations are safeguarded from this risk.
Affected Version(s)
Grafana Enterprise 11.6.0 <= 11.6.17
Grafana Enterprise 12.2.0 <= 12.2.11
Grafana Enterprise 12.3.0 <= 12.3.11