CVE-2026-33376
published 2026-05-13CVE-2026-33376: When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate…
PriorityP344high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.28%
20.7th percentile
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | >= 12.2.0 < 12.2.8 | 12.2.8 |
| grafana | grafana | >= 12.3.0 < 12.3.6 | 12.3.6 |
| grafana | grafana | >= 12.4.0 < 12.4.3 | 12.4.3 |
| grafana | grafana | >= 8.5.0 < 11.6.14 | 11.6.14 |
| grafana | grafana_oss | >= 11.6.14 < 11.6.14+security-04 | 11.6.14+security-04 |
| grafana | grafana_oss | 12.0.0 – 12.2.8 | — |
| grafana | grafana_oss | >= 12.2.8 < 12.2.8+security-04 | 12.2.8+security-04 |
| grafana | grafana_oss | 12.3.0 – 12.3.6 | — |
| grafana | grafana_oss | >= 12.3.6 < 12.3.6+security-04 | 12.3.6+security-04 |
| grafana | grafana_oss | 12.4.0 – 12.4.3 | — |
| grafana | grafana_oss | >= 12.4.3 < 12.4.3+security-02 | 12.4.3+security-02 |
| grafana | grafana_oss | 13.0.0 – 13.0.1 | — |
| grafana | grafana_oss | >= 13.0.1 < 13.0.1+security-01 | 13.0.1+security-01 |
| grafana | grafana_oss | 9.4.0 – 11.6.14 | — |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhceph | grafana-rhel10 | — | — |
| rhceph | grafana-rhel9 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default
vendor_redhat·2026-05-13·CVSS 7.4
CVE-2026-33376 [HIGH] CWE-183 grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default
grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
A flaw in Grafana's Auth Proxy IPv6 allow-list incorrectly defaults to a broad /32 subnet mask instead of a strict /128. This misconfiguration allows remote attackers to bypass access restrictions, potentially leading to unauthorized access and data manipulation.
Statement: A flaw in Grafana's Auth Proxy IPv6 allow-list defaults to an overly broad /32 mask, potentially allowing unauthorized access. This strictly
GHSA
GHSA-3r2p-7499-27q3: When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses
ghsa_unreviewed·2026-05-13
CVE-2026-33376 [HIGH] CWE-1188 GHSA-3r2p-7499-27q3: When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-33376 grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default [fedora-all]
bugzilla·2026-07-16·CVSS 7.4
CVE-2026-33376 [HIGH] CVE-2026-33376 grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default [fedora-all]
CVE-2026-33376 grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
Bugzilla
CVE-2026-33376 grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default
bugzilla·2026-05-13·CVSS 7.4
CVE-2026-33376 [HIGH] CVE-2026-33376 grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default
CVE-2026-33376 grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
2026-05-13
Published