Security Flaw in Auth Proxy Feature of Grafana
CVE-2026-33376

7.4HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
13 May 2026

What is CVE-2026-33376?

A configuration vulnerability exists in the Auth Proxy feature of Grafana where the default IPv6 allow-list uses /32 addresses. This could lead to improper access controls if not configured correctly. To mitigate this issue, administrators should explicitly specify a mask, commonly /128, for addresses on the allow-list. It is important to note that this issue is restricted to the Auth Proxy feature; other services like Okta, SAML, and LDAP are not impacted.

Affected Version(s)

Grafana OSS OnPrem 9.4.0 <= 11.6.14

Grafana OSS OnPrem 11.6.14 < 11.6.14+security-04

Grafana OSS OnPrem 12.0.0 <= 12.2.8

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.