Skip to content
Critical Vulnerability Affecting Grafana Enterprise

Critical Vulnerability Affecting Grafana Enterprise

Csa.Sg November 22, 2025

Grafana has released security updates to address a critical vulnerability (CVE-2025-41115) in Grafana Enterprise. Users and administrators of affected product versions are advised to update to the latest version immediately.

Grafana has released security updates to address a critical vulnerability (CVE-2025-41115) in Grafana Enterprise. This vulnerability resides in the System for Cross-domain Identity Management (SCIM) component that allows automated user provisioning and management. It has a maximum Common Vulnerability Scoring System (CVSSv3.1) score of 10 out of 10.

If SCIM provisioning is enabled and configured, successful exploitation of the vulnerability could allow a malicious or compromised SCIM client to furnish a user with a numeric external ID to override internal user IDs, resulting in impersonation or privileges escalation.

The vulnerability impacts Grafana Enterprise running on the following versions:

Grafana Enterprise 12.0.0 to 12.2.1

The vulnerability will also only exist if the following conditions are met:

enableSCIM feature flag set to true

user_sync_enabled config option in the [auth.scim] block set to true

Users and administrators of affected product versions are advised to update to the latest version immediately.

Extracted Entities

Companies (1)