Authentication Bypass Vulnerability in Grafana Auth Proxy by Grafana Labs
CVE-2026-14199

7.1HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
2 September 2026

What is CVE-2026-14199?

Grafana instances that utilize Auth Proxy authentication while having identity caching enabled are at risk due to a design flaw. The proxy cache produces a concatenated key from the username and forwarded identity attributes without a delimiter, causing potential key collisions. This vulnerability allows an authenticated user to manipulate their identity attributes in a way that could trick the system into granting them unauthorized access to a higher-privileged user's session. As a result, they may be able to authenticate as another user, even up to the Administrator level, leading to serious security implications.

Affected Version(s)

Grafana Enterprise 11.0.0 <= 11.6.17

Grafana Enterprise 12.0.0 <= 12.2.11

Grafana Enterprise 12.3.0 <= 12.3.11

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rebelarch (Researcher)
.