Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14199

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

On instances using Auth Proxy header authentication ([auth.proxy]) with identity caching enabled (sync_ttl > 0), two distinct user identities could produce the same cache key. An authenticated low-privileged user able to influence their own forwarded identity attributes could be served a higher-privileged user's cached session and act as that user for the duration of the cache TTL. Default configurations are not affected.

Меры по смягчению последствий

Set [auth.proxy] sync_ttl = 0 to disable the identity cache (identity is then synced on every request), or upgrade to a fixed version: 11.0.0+, 12.4.10+ (12.4.x), 13.0.8+ (13.0.x), 13.1.5+ (13.1.x), or 13.2.1+ (13.2.x and newer — 13.2.0 itself is still vulnerable).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Under investigation
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Affected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 9rhceph/grafana-rhel10Affected
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2521850grafana: Grafana: Session takeover via Auth Proxy cache key collision

EPSS

Процентиль: 24%
0.00313
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
22 дня назад

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

CVSS3: 7.1
github
22 дня назад

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

EPSS

Процентиль: 24%
0.00313
Низкий

7.1 High

CVSS3