当在 Grafana Enterprise 中启用 SAML IdP 发起的登录时,SAML 库会跳过对所有 SAML 响应(包括 SP 发起的登录)中 字段的验证。这会移除重放攻击防护,使得攻击者若获取到一条有效的已签名 SAML 断言,便可重放该断言,从而以受害者用户的身份建立会话。仅那些启用了 SAML 设置的实例受影响;该设置默认关闭,且 Grafana OSS 不受影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana Enterprise | 11.6.0 ~ 11.6.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14199 | 7.1 HIGH | CVE-2026-14199 CVE Record |
| CVE-2026-19475 | 6.5 MEDIUM | CVE-2026-19475 CVE Record |
No comments yet