Skip to main content
HIGH

CVE-2026-14199

CVSS v3

7.1

HIGH

EPSS Score

0.3 %

exploit probability, as of 2026-09-29

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication by

Technical details

Published
2026-09-02
Last Modified
2026-09-03

Frequently asked questions

What is CVE-2026-14199?

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication by

Is CVE-2026-14199 actively exploited?

Active exploitation of CVE-2026-14199 has not been confirmed. Its EPSS score was 0.3% on 2026-09-29, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-14199?

CVE-2026-14199 has a CVSS v3 base score of 7.1 (HIGH severity).

Is CVE-2026-14199 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key