Authentication Bypass by Capture-replay in Grafana Enterprise - CVE-2026-12704
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain a session as the victim user.
The vulnerability exists due to improper validation of the InResponseTo field in the SAML library when processing SAML responses. A remote attacker can replay a valid signed SAML assertion to gain a session as the victim user.
User interaction is required, and only instances with the allow_idp_initiated SAML setting enabled are affected.