PT-2026-84754 · Grafana · Grafana

·

CVE-2026-14199

·

Published

2026-09-02

·

Updated

2026-09-08

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Grafana (affected versions not specified)
Description Self-managed instances using Auth Proxy authentication with identity caching enabled (where sync ttl is greater than zero) are susceptible to an authentication bypass. The issue occurs because the Auth Proxy cache key concatenates the username and forwarded identity attributes without a delimiter, allowing distinct identities to collide on a single key. An authenticated user can spoof a higher-privileged user, including an Administrator, by shaping their own attributes to collide with a live cache entry of the target user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-2026-14199
CVE-2026-14199
OPENSUSE-SU-2026:11684-1

Affected Products

Grafana