Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
References
| Link | Resource |
|---|---|
| https://grafana.com/security/security-advisories/cve-2026-14199 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-09-02 16:17
Updated : 2026-09-15 18:23
NVD link : CVE-2026-14199
Mitre link : CVE-2026-14199
CVE.ORG link : CVE-2026-14199
JSON object : View
Products Affected
grafana
- grafana
