CVE-2026-14199

Aliases:CGA-4w25-3fc9-jjjxCGA-6q8p-9rxm-rp98CGA-f7p8-v8h9-cf53CGA-j59f-rmqr-mgcwCGA-pr46-4mg8-9fmgCGA-4jh3-fffq-3rhvCGA-c2q6-38hg-rwv6CGA-c6vp-59cg-fvwrCGA-cmqq-crq2-qqr4CGA-grxf-r352-3pcjCGA-jjrh-x55h-939rCGA-mh4p-7jp3-2h3wCGA-x88q-89gw-f37hCGA-5cw7-4xc8-rgqxCGA-2cmg-rh6m-f9gqCGA-2g38-frjr-xxmmCGA-qgvx-hvr6-2mqvCGA-rh37-r6w8-j7c9CGA-3f7g-wm67-4mc5CGA-3vgj-3857-h4p7CGA-3wph-v55r-m96jCGA-4c7m-9qhj-gmqwCGA-4cg9-7cmw-jfm5CGA-5957-p5g5-rhqgCGA-5cmm-jprw-6fvcCGA-78w6-p5c3-w9x8CGA-7f98-7wqq-prj3CGA-7qvg-ppp2-vgqvCGA-8gx2-95fx-rjfgCGA-8jw2-fhp7-qm28CGA-99fv-86xh-g4wvCGA-9vp5-gjvc-9p2rCGA-fg33-jwcf-h5w2CGA-fg3c-vmv8-rw8xCGA-fgcp-xp5m-qc4cCGA-g9fr-8798-vf62CGA-gxc6-5mpw-w3qqCGA-jcrg-22fh-39x7CGA-mc4h-v85v-xfq9CGA-mrfp-w2fq-5g8vCGA-ppff-vfr7-hf66CGA-pvch-mc5x-cw8gCGA-qp7g-m4j2-rvqgCGA-vcxw-v539-5jpgCGA-vx66-mv5f-8qv7CGA-wq8g-jj97-36rqCGA-wqjg-v6r8-c6jxCGA-xcvp-v3fj-xjw6CGA-xm3m-8frf-5mwrCGA-xwqq-chwr-fvp8CGA-xx5m-xcch-vm25CGA-33c9-rgrp-x6wjCGA-2wj3-jrqq-jq9hCGA-5837-xxwj-4857CGA-68jm-jw8v-2vp4CGA-7c98-hm9v-3j7mCGA-8gvp-886r-x2xjCGA-9mfg-cxhf-ch3jCGA-hw2x-m2hm-jwjhCGA-j968-qwc8-8mc3CGA-mww2-5w4c-7qrpCGA-whx4-j3w6-53c5CGA-m52g-h8h7-gf9qCGA-32fr-787r-v28xCGA-32fx-wp3f-cm23CGA-7265-569g-9gxjCGA-72mf-85pp-22xjCGA-84r2-q32g-mg8qCGA-97jf-rxcc-2hgwCGA-h276-xv52-qp4vCGA-m5mw-ph7f-qw8rCGA-m5qj-v975-4vvv
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 02 Sept 2026, 16:06
Last modified:03 Sept 2026, 08:07

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
0.31% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Sept 2026, 16:06
Published
Vulnerability first disclosed
03 Sept 2026, 08:07
Last Modified
Vulnerability information updated

Description

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

CVSS Metrics

  • v3.1HIGHScore: 7.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.31% Percentile: 24%

Techniques & Countermeasures

  • CWE-290Authentication Bypass by Spoofing

    This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • CWE-1023Incomplete Comparison with Missing Factors

    The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.

Affected Systems

  • chainguardgrafana-11.6

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.2

    all

  • chainguardgrafana-12.3

    all

  • chainguardgrafana-12.4

    all | < 12.4.10-r2

  • chainguardgrafana-13.0

    all

  • chainguardgrafana-13.1

    all

  • chainguardgrafana-fips-11.6

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.2

    all

  • chainguardgrafana-fips-12.3

    all

  • chainguardgrafana-fips-13.1

    all

  • chainguardgrafana-geomys-fips-13.1

    all

  • chainguardpercona-grafana

    all

  • wolfigrafana-12.3

    all

  • wolfigrafana-12.4

    all | < 12.4.10-r2

  • wolfigrafana-13.0

    all

  • grafanagrafana

    < 11.0.0 | ≥ 12.4.10, < 13.0.0 | ≥ 13.0.8, < 13.1.0 | ≥ 13.1.5, < 13.2.0

  • grafanagrafana enterprise

    ≥ 11.0.0, ≤ 11.6.17 | ≥ 12.0.0, ≤ 12.2.11 | ≥ 12.3.0, ≤ 12.3.11 | ≥ 12.4.0, ≤ 12.4.9 | ≥ 13.0.0, ≤ 13.0.7 | ≥ 13.1.0, ≤ 13.1.4 | 13.2.0

  • grafanagrafana oss

    ≥ 11.0.0, ≤ 11.6.17 | ≥ 12.0.0, ≤ 12.2.11 | ≥ 12.3.0, ≤ 12.3.11 | ≥ 12.4.0, ≤ 12.4.9 | ≥ 13.0.0, ≤ 13.0.7 | ≥ 13.1.0, ≤ 13.1.4 | 13.2.0

References (1)