CVE-2026-12704: Grafana Enterprise

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected.

Affected products

  • Grafana Grafana Enterprise: from 11.6.0, up to and including 11.6.17; from 12.2.0, up to and including 12.2.11; from 12.3.0, up to and including 12.3.11; from 12.4.0, up to and including 12.4.10; from 13.0.0, up to and including 13.0.7; from 13.1.0, up to and including 13.1.4; …

Published 2026-09-02. Last modified 2026-09-03.