CVE-2025-41115: A Maximum-Severity Privilege Escalation Vulnerability in the Grafana SCIM Component
ID: 188615c3-b0e5-5578-867b-be75c10606dd
STIX ID: report--188615c3-b0e5-5578-867b-be75c10606dd
Feed Name: SOC Prime Blog
Threat Score
A critical Grafana SCIM vulnerability (CVE-2025-41115, CVSS 10.0) affects Grafana Enterprise 12.0.0–12.2.1 when SCIM provisioning is enabled and user_sync_enabled is set; a malicious SCIM client can provision a numeric externalId that maps to internal user IDs, potentially allowing user impersonation or admin privilege escalation. Grafana has released urgent patches and organizations are advised to update immediately to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
