CVE-2026-12704

EUVD-2026-70197
When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GRAFANACNA
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
grafanagrafana
11.6.0 ≤
𝑥
≤ 11.6.17
CNA
grafanagrafana
12.2.0 ≤
𝑥
≤ 12.2.11
CNA
grafanagrafana
12.3.0 ≤
𝑥
≤ 12.3.11
CNA
grafanagrafana
12.4.0 ≤
𝑥
≤ 12.4.10
CNA
grafanagrafana
13.0.0 ≤
𝑥
≤ 13.0.7
CNA
grafanagrafana
13.1.0 ≤
𝑥
≤ 13.1.4
CNA
grafanagrafana
𝑥
≤ 13.2.0
CNA