CVE-2026-33376

Aliases:CGA-2v6w-xf8x-2mgrCGA-3758-2rf5-h72pCGA-4mmr-36hf-px2mCGA-7rp7-46rj-jf28CGA-8rvf-wjx9-rmg5CGA-j582-5m9c-84hhCGA-2c39-p5jq-c68qCGA-2v89-2h9j-87f3CGA-3fgf-c4x6-w34jCGA-3hvq-gq86-5mhrCGA-3wv8-64h3-27hrCGA-4ch8-cc8q-vcgvCGA-4r2h-9ppm-6vxgCGA-5g4q-42rf-m8q5CGA-5m7r-9wc4-pmfqCGA-64mw-484h-8hx6CGA-6wmv-5p75-4xp7CGA-7c3q-h4pj-hrj5CGA-8382-vg4w-fg5wCGA-85hr-r7j9-6v89CGA-8wvq-4f2q-f5v4CGA-9vch-5v2c-9v3jCGA-ch9g-x7ch-gp9pCGA-jrgq-qqvj-wfx8CGA-jvxw-87r4-hcj9CGA-jxmg-rx2v-m3mrCGA-m3mq-qgpq-89rrCGA-m5pm-wgc8-3mf9CGA-m7vh-99rq-c2f4CGA-p3q8-x8fw-33gqCGA-p4j8-jxc9-hpxpCGA-q3rr-w94x-94mfCGA-qgxc-939m-4r3gCGA-rwgf-vg65-2hvvCGA-v4wg-6mf3-7pvvCGA-w2pp-9595-6cjjCGA-w43w-wv37-qc7rCGA-w69m-fxjv-hhgpCGA-wcc3-2jpg-j3ccCGA-wrwc-f3fg-cjxfCGA-xvg8-247h-p5gjCGA-xvmw-6r29-p68f
Analyzed
Published: 13 May 2026, 19:28
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.4 HIGH
v3.1 (cve.org)
EPSS Score
0.28% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 May 2026, 19:28
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.28% Percentile: 21%

Techniques & Countermeasures

  • CWE-1188Initialization of a Resource with an Insecure Default

    The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Affected Systems

  • chainguardgrafana-12.0

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.4

    < 12.4.3.02-r0

  • chainguardgrafana-fips-12.0

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.4

    < 12.4.4-r0

  • wolfigrafana-12.4

    < 12.4.3.02-r0

  • grafanagrafana

    ≥ 8.5.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1

  • grafanagrafana oss

    ≥ 9.4.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01

References (3)