CVE-2023-3128: Grafana
Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
Affected products
- Grafana Grafana: from 6.7.0, before 8.5.27 (fixed in 8.5.27); from 9.2.0, before 9.2.20 (fixed in 9.2.20); from 9.3.0, before 9.3.16 (fixed in 9.3.16); from 9.4.0, before 9.4.13 (fixed in 9.4.13); from 9.5.0, before 9.5.4 (fixed in 9.5.4)
Published 2023-06-22. Last modified 2026-06-17.