THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14199 (HIGH 7.1) — Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collid

[NVD] CVE-2026-14199 (HIGH 7.1) — Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collid

mednvdPublished 2026-09-02

CVE-2026-14199 CVSS: 7.1 HIGH Published: 2026-09-02T16:17:14.517

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their o

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14199