Skip to content
Critical Grafana SCIM Vulnerability Allows Privilege Escalation

Critical Grafana SCIM Vulnerability Allows Privilege Escalation

First seen 2 Dec 2025, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Grafana Labs has issued critical patches for a severe vulnerability, CVE-2025-41115, affecting Grafana Enterprise versions 12.0.0 to 12.2.1. The flaw in the SCIM provisioning feature could enable attackers to escalate privileges or impersonate users if specific configurations are enabled. Organizations using affected versions are urged to update immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (6)

Following this threat?

Track Kimsuky, Xillen Stealer and Grafana in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed