Grafana has released security updates to address a critical vulnerability (CVE-2025-41115) in Grafana Enterprise. Users and administrators of affected product versions are advised to update to the latest version immediately.
Grafana has released security updates to address a critical vulnerability (CVE-2025-41115) in Grafana Enterprise. This vulnerability resides in the System for Cross-domain Identity Management (SCIM) component that allows automated user provisioning and management. It has a maximum Common Vulnerability Scoring System (CVSSv3.1) score of 10 out of 10.
If SCIM provisioning is enabled and configured, successful exploitation of the vulnerability could allow a malicious or compromised SCIM client to furnish a user with a numeric external ID to override internal user IDs, resulting in impersonation or privileges escalation.
The vulnerability impacts Grafana Enterprise running on the following versions:
Grafana Enterprise 12.0.0 to 12.2.1
The vulnerability will also only exist if the following conditions are met:
enableSCIM feature flag set to true
user_sync_enabled config option in the [auth.scim] block set to true
Users and administrators of affected product versions are advised to update to the latest version immediately.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
