Security Flaw in Auth Proxy Feature of Grafana
CVE-2026-33376
7.4HIGH
What is CVE-2026-33376?
A configuration vulnerability exists in the Auth Proxy feature of Grafana where the default IPv6 allow-list uses /32 addresses. This could lead to improper access controls if not configured correctly. To mitigate this issue, administrators should explicitly specify a mask, commonly /128, for addresses on the allow-list. It is important to note that this issue is restricted to the Auth Proxy feature; other services like Okta, SAML, and LDAP are not impacted.
Affected Version(s)
Grafana OSS OnPrem 9.4.0 <= 11.6.14
Grafana OSS OnPrem 11.6.14 < 11.6.14+security-04
Grafana OSS OnPrem 12.0.0 <= 12.2.8