Executive brief
Grafana is an open-source platform for monitoring and observability. A security flaw in its Auth Proxy feature incorrectly handles IPv6 address restrictions, potentially allowing unauthorized users to bypass security controls if they are on the same broad network segment. This could lead to unauthorized access to sensitive dashboards and administrative functions.
Technical details
A vulnerability exists in Grafana's Auth Proxy feature due to insecure default initialization of IPv6 allow-lists (CWE-1188). When an IPv6 address is provided without an explicit subnet mask, the system defaults to a /32 prefix instead of the expected /128 (single host) mask. This significantly broadens the range of allowed addresses, potentially permitting millions of unintended IPv6 addresses to authenticate via the proxy. The attack requires the attacker to be within the broad /32 range and for the Auth Proxy to be enabled. Other authentication methods like SAML or LDAP are not affected. Patches are available in versions 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1.
Affected products
- Grafana Labs Grafana 8.5.0 to 11.6.13, 12.2.0 to 12.2.7, 12.3.0 to 12.3.5, 12.4.0 to 12.4.2, 13.0.0
Timeline
- 2026-05-13: advisory: Initial advisory published by Grafana Labs
- 2026-05-13: disclosed
- 2026-06-02: patched: NVD updated with specific affected version ranges