# CVE-2026-12704

## Summary

- **CVE ID:** CVE-2026-12704
- **Severity:** MEDIUM
- **CVSS Score:** 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N)
- **CWE:** CWE-294
- **Published:** Sep 2, 2026
- **Last Modified:** Sep 3, 2026

## Description

When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected.

## Affected Products

- Grafana — Grafana Enterprise (11.6.0)
- Grafana — Grafana Enterprise (12.2.0)
- Grafana — Grafana Enterprise (12.3.0)
- Grafana — Grafana Enterprise (12.4.0)
- Grafana — Grafana Enterprise (13.0.0)
- Grafana — Grafana Enterprise (13.1.0)
- Grafana — Grafana Enterprise (13.2.0)

## References

- [CNA](https://grafana.com/security/security-advisories/cve-2026-12704)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._