Skip to content
Maximum severity Grafana vulnerability fixed

Maximum severity Grafana vulnerability fixed

Scworld November 24, 2025

Updates have been issued for a maximum severity flaw in Grafana Enterprise's System for Cross-domain Identity Management component, tracked as CVE-2025-41115, which could be leveraged to elevate privileges or spoof users, according to The Hacker News .

All Grafana Enterprise versions 12.0.0 to 12.2.1 are affected by the vulnerability, which could be exploited if both the enableSCIM feature flag and user_sync_enabled config option in the [auth.scim] block are set to true, said Grafana's Vardan Torosyan.

"Grafana maps the SCIM externalId directly to the internal user.uid; therefore, numeric values (e.g. '1') may be interpreted as internal numeric user IDs. In specific cases, this could allow the newly provisioned user to be treated as an existing internal account, such as the Admin, leading to potential impersonation or privilege escalation," Torosyan added.

Organizations using Grafana Enterprises impacted by the security issue were urged to immediately implement newer versions of the software.

Extracted Entities

Companies (1)