Improper access control in Grafana - CVE-2026-33376
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass IP-based access restrictions for the Auth Proxy feature.
The vulnerability exists due to improper access control in the Auth Proxy IPv6 allow-list handling when evaluating IPv6 addresses without an explicitly specified mask. A remote attacker can use an IPv6 address that matches the unintended default /32 range to bypass IP-based access restrictions for the Auth Proxy feature.
Only the Auth Proxy feature is affected; other authentication methods such as Okta, SAML, and LDAP are unaffected.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
grafana (Red Hat package)
How to mitigate CVE-2026-33376
grafana (Red Hat package) - update to 10.2.6-28.el10_2.4