Thehackernews Critical Grafana SCIM Vulnerability Allows Privilege Escalation
Article Content
Browse articles
Grafana Labs has issued critical patches for a severe vulnerability (CVE-2025-41115) in its SCIM provisioning feature, which could enable attackers to escalate privileges or impersonate users. The flaw affects Grafana Enterprise versions 12.0.0 through 12.2.1 when specific configurations are enabled. Organizations are urged to update immediately to mitigate risks associated with this critical vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (6)
Following this threat?
Track Kimsuky, Xillen Stealer and Grafana in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New ScreenConnect Flaw Enables Malware Spread via Rogue Clients ConnectWise has identified a critical vulnerability in ScreenConnect Remote Access affecting both cloud and on-premises deployments. The flaw, which impacts file transfer functionality, allows attackers to deploy rogue ScreenConnect clients that spread malware to connected systems. This malware is propagated through…
Kimsuky Hacking Group Uses AI Coding Agent for Malware Decoys The North Korea-linked hacking group Kimsuky has been confirmed to use an open-source AI coding agent named 'opencode' to create decoy documents for malware distribution. A South Korean security firm, Genians, reported that analysis of 13 malicious files revealed that these documents were disguised as financial and…