Executive brief
Grafana is an observability and analytics platform used to visualize business and infrastructure metrics. A flaw in its Auth Proxy authentication system allows an authenticated user to impersonate administrators and other high-privilege accounts by crafting specially-formed identity attributes that collide with cached user sessions. This could lead to complete compromise of dashboards, alerts, and sensitive operational data.
Technical details
The vulnerability is an authentication bypass caused by an insufficiently unique cache key generation in Grafana's Auth Proxy authentication handler. When identity caching is enabled (sync_ttl > 0), the cache key concatenates username and forwarded identity attributes without a delimiter, allowing distinct identities to produce identical cache keys. An authenticated attacker can craft their own identity attributes to collide with a higher-privileged user's cached entry, causing the system to authenticate them as that privileged user (up to Administrator). The attack requires: (1) Auth Proxy authentication enabled, (2) identity caching enabled with sync_ttl > 0, (3) the target user's cache entry to be live, and (4) the attacker to be an authenticated user capable of influencing their own identity attributes. Patches are available in versions 12.4.10+, 13.0.8+, and 13.1.5+.
Affected products
- Grafana Grafana Enterprise <11.0.0; >=12.4.10 <13.0.0; >=13.0.8 <13.1.0; >=13.1.5 <13.2.0; >=13.2.1
Timeline
- 2026-09-02: disclosed
- 2026-09-02: advisory