Improper Authentication in Grafana Enterprise - CVE-2026-14199
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authentication and impersonate higher-privileged users.
The vulnerability exists due to improper cache key construction in the Auth Proxy identity cache when generating cache keys from usernames and forwarded identity attributes. A remote user can shape their identity attributes to collide with another user\'s cache key to bypass authentication and impersonate higher-privileged users.
Only self-managed instances with Auth Proxy authentication and identity caching enabled with sync_ttl greater than zero are affected. Exploitation requires a higher-privileged user\'s cache entry to be live.