logo

CVE-2025-41115: A Maximum-Severity Privilege Escalation Vulnerability in the Grafana SCIM Component 

ID: 188615c3-b0e5-5578-867b-be75c10606dd

STIX ID: report--188615c3-b0e5-5578-867b-be75c10606dd

Feed Name: SOC Prime Blog

Threat Score
85/100

Date Published: 2025-11-24

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

A critical Grafana SCIM vulnerability (CVE-2025-41115, CVSS 10.0) affects Grafana Enterprise 12.0.0–12.2.1 when SCIM provisioning is enabled and user_sync_enabled is set; a malicious SCIM client can provision a numeric externalId that maps to internal user IDs, potentially allowing user impersonation or admin privilege escalation. Grafana has released urgent patches and organizations are advised to update immediately to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.