CVE-2026-14199: CVE Record

Published Sep 2, 2026
·
Updated

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syncttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

Affected Software

1 affected component
Grafana Grafana

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    For self-managed Grafana using Auth Proxy authentication, set identity caching so that sync_ttl is not greater than zero (disable/stop identity caching) to avoid the affected cache key behavior.

    Grafana Auth Proxy identity caching (sync_ttl) = greater than zero

Event History

Sep 2, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Only self-managed Grafana instances using Auth Proxy authentication with identity caching enabled are affected. Identity caching is enabled when sync_ttl is greater than zero.

2

What does an attacker need to exploit this?

The attacker must already be authenticated and able to shape their own forwarded identity attributes. Exploitation also requires a higher-privileged user’s matching cache entry to be live at the time of the collision.

3

What can be done if patching is not immediately possible?

Disable Auth Proxy identity caching by setting sync_ttl to zero, or stop using Auth Proxy authentication. The affected condition requires both Auth Proxy and a sync_ttl greater than zero.

4

How can administrators determine whether they are currently affected?

Review the Grafana authentication configuration for Auth Proxy usage and check whether sync_ttl is set above zero. If either Auth Proxy is not used or sync_ttl is zero, the instance is not affected according to the advisory details.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203