CVE-2026-14199: Session takeover via Auth Proxy cache key collision

Published Sep 2, 2026
·
Updated

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syncttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

Affected Software

5 affected components
Grafana Grafana
Grafana Grafana<11.0.0
Grafana Grafana>=12.4.10<13.0.0
Grafana Grafana>=13.0.8<13.1.0
Grafana Grafana>=13.1.5<13.2.0

Event History

Sep 2, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Only self-managed Grafana instances using Auth Proxy authentication with identity caching enabled are affected. Identity caching is enabled when sync_ttl is greater than zero.

2

What does an attacker need to exploit this?

The attacker must already be authenticated and able to shape their own forwarded identity attributes. Exploitation also requires a higher-privileged user’s matching cache entry to be live at the time of the collision.

3

What can be done if patching is not immediately possible?

Disable Auth Proxy identity caching by setting sync_ttl to zero, or stop using Auth Proxy authentication. The affected condition requires both Auth Proxy and a sync_ttl greater than zero.

4

How can administrators determine whether they are currently affected?

Review the Grafana authentication configuration for Auth Proxy usage and check whether sync_ttl is set above zero. If either Auth Proxy is not used or sync_ttl is zero, the instance is not affected according to the advisory details.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203