Auth Proxy Cache Key Collision in Grafana Allows Auth Bypass (CVE202614199)
CVE-2026-14199 Published on September 2, 2026
Session takeover via Auth Proxy cache key collision
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
Weakness Types
Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
Incomplete Comparison with Missing Factors
The software performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors. An incomplete comparison can lead to resultant weaknesses, e.g., by operating on the wrong object or making a security decision without considering a required factor.
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-14199 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-14199
Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.
Affected Versions
Grafana Enterprise:- Version 11.0.0, <= 11.6.17 is affected.
- Version 12.0.0, <= 12.2.11 is affected.
- Version 12.3.0, <= 12.3.11 is affected.
- Version 12.4.0, <= 12.4.9 is affected.
- Version 13.0.0, <= 13.0.7 is affected.
- Version 13.1.0, <= 13.1.4 is affected.
- Version 13.2.0, <= 13.2.0 is affected.
- Version 11.0.0, <= 11.6.17 is affected.
- Version 12.0.0, <= 12.2.11 is affected.
- Version 12.3.0, <= 12.3.11 is affected.
- Version 12.4.0, <= 12.4.9 is affected.
- Version 13.0.0, <= 13.0.7 is affected.
- Version 13.1.0, <= 13.1.4 is affected.
- Version 13.2.0, <= 13.2.0 is affected.