THREAT OPS › Threat News › [NVD] CVE-2026-14199 (HIGH 7.1) — Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collid
[NVD] CVE-2026-14199 (HIGH 7.1) — Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collid
CVE-2026-14199 CVSS: 7.1 HIGH Published: 2026-09-02T16:17:14.517
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their o
Indicators of compromise
- CVE-2026-14199cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14199