« Volver al listado

CVE-2026-14199

Estado: AnalizadaAlta (8.1)—

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso a red adyacente (PR:L) contra servicio remoto (Auth Proxy). El atacante suplanta identidades en caché para elevar permisos hasta administrador, logrando autenticación falsa y control de cuentas.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-14199",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-14199",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-02T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@grafana.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@grafana.com",
      "affectedData": [
        {
          "vendor": "Grafana",
          "product": "Grafana Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "11.6.17"
            },
            {
              "status": "affected",
              "version": "12.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "12.2.11"
            },
            {
              "status": "affected",
              "version": "12.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "12.3.11"
            },
            {
              "status": "affected",
              "version": "12.4.0",
              "versionType": "semver",
              "lessThanOrEqual": "12.4.9"
            },
            {
              "status": "affected",
              "version": "13.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "13.0.7"
            },
            {
              "status": "affected",
              "version": "13.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "13.1.4"
            },
            {
              "status": "affected",
              "version": "13.2.0",
              "versionType": "semver",
              "lessThanOrEqual": "13.2.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Grafana",
          "product": "Grafana OSS",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "11.6.17"
            },
            {
              "status": "affected",
              "version": "12.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "12.2.11"
            },
            {
              "status": "affected",
              "version": "12.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "12.3.11"
            },
            {
              "status": "affected",
              "version": "12.4.0",
              "versionType": "semver",
              "lessThanOrEqual": "12.4.9"
            },
            {
              "status": "affected",
              "version": "13.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "13.0.7"
            },
            {
              "status": "affected",
              "version": "13.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "13.1.4"
            },
            {
              "status": "affected",
              "version": "13.2.0",
              "versionType": "semver",
              "lessThanOrEqual": "13.2.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-02T16:17:14.517",
  "references": [
    {
      "url": "https://grafana.com/security/security-advisories/cve-2026-14199",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@grafana.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@grafana.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        },
        {
          "lang": "en",
          "value": "CWE-1023"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing)."
    }
  ],
  "lastModified": "2026-09-15T18:23:02.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D828FF4-D41A-4D39-9293-1A65FB9CE0DA",
              "versionEndExcluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "426531C3-A27D-4DA7-81EA-00DAE298707A",
              "versionEndExcluding": "13.0.0",
              "versionStartIncluding": "12.4.10"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46FC7B23-2EB6-4335-BE5B-E32512E9D30C",
              "versionEndExcluding": "13.1.0",
              "versionStartIncluding": "13.0.8"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "016BB9D1-BC78-4AC1-913C-10B535CF0447",
              "versionEndExcluding": "13.2.0",
              "versionStartIncluding": "13.1.5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@grafana.com"
}