Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected. | |
| Title | CVE-2026-12704 CVE Record | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-09-02T16:05:42.965Z
Reserved: 2026-06-19T10:24:45.152Z
Link: CVE-2026-12704
No data.
Status : Received
Published: 2026-09-02T16:17:14.383
Modified: 2026-09-02T16:17:14.383
Link: CVE-2026-12704
No data.
OpenCVE Enrichment
No data.
-
CWE-294
Authentication Bypass by Capture-replay