CVEFinder.io

CVE-2026-33376

⚠️ high
🔍 Scan for this CVE
Summary

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS Score
7.4
High
EPSS Score
0.0
Exploit Probability
Published Date
2026-05-13
First Seen: 2026-05-17
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 57.0% of all 328,009 vulnerabilities in our database.

#141,114
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 15, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-06-02
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE IDs (Weakness Types)

📦 Affected Products 10

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-28374 🔶 medium 4.3 0.0 Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t... 2026-05-13
CVE-2026-28376 🔶 medium 6.5 0.0 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req... 2026-05-13
CVE-2026-28379 🔶 medium 6.5 0.0 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur... 2026-05-13
CVE-2026-28380 🔶 medium 6.5 0.0 Any Editor could delete any snapshot, even if they have no access to read or write them. 2026-05-13
CVE-2026-28383 🔶 medium 6.5 0.0 A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b... 2026-05-13
CVE-2026-33377 ⚠️ high 7.1 0.0 An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr... 2026-05-13
These CVEs affect the same products