Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14199— CVE-2026-14199 CVE Record

Quick assessment

Affected
Grafana Grafana Enterprise
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

仅受影响的系统是启用了 Auth Proxy 认证且身份缓存功能开启(即 大于零)的自建 Grafana 实例。Auth Proxy 的缓存键将用户名和转发的身份属性直接拼接,中间没有使用分隔符,导致不同的身份可能在同一个缓存键上发生冲突。当一个已认证用户能够操控自身的身份属性,使其与某个权限更高的用户(其缓存条目当前仍然有效)的身份属性发生冲突时,该用户就会以那位高权限用户的身份通过身份验证,最高可提升至管理员权限(通过身份伪造实现身份验证绕过)。

CVSS 7.1 · High

Possible ATT&CK Techniques 2 AI

T1079 T1079.004
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14199

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-14199 CVE Record
Source: CVE Program / CVE List V5
Vulnerability Description
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Grafana Grafana Enterprise 11.0.0 ~ 11.6.17 -
Grafana Grafana OSS 11.0.0 ~ 11.6.17 -

II. Public POCs for CVE-2026-14199

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14199

登录查看更多情报信息。

Vendor Pages for CVE-2026-14199 (1)

Same Patch Batch · Grafana · 2026-09-02 · 3 CVEs total

CVE-2026-12704 6.8 MEDIUM CVE-2026-12704 CVE Record
CVE-2026-19475 6.5 MEDIUM CVE-2026-19475 CVE Record

IV. Related Vulnerabilities

V. Comments for CVE-2026-14199

No comments yet


Leave a comment