Authentication Bypass Vulnerability in Grafana Auth Proxy by Grafana Labs
CVE-2026-14199
7.1HIGH
Key Information:
- Vendor
Grafana
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-14199?
Grafana instances that utilize Auth Proxy authentication while having identity caching enabled are at risk due to a design flaw. The proxy cache produces a concatenated key from the username and forwarded identity attributes without a delimiter, causing potential key collisions. This vulnerability allows an authenticated user to manipulate their identity attributes in a way that could trick the system into granting them unauthorized access to a higher-privileged user's session. As a result, they may be able to authenticate as another user, even up to the Administrator level, leading to serious security implications.
Affected Version(s)
Grafana Enterprise 11.0.0 <= 11.6.17
Grafana Enterprise 12.0.0 <= 12.2.11
Grafana Enterprise 12.3.0 <= 12.3.11