logo

Grafana warns of max severity admin spoofing vulnerability

ID: aa3acc2e-b32c-50cd-a159-a1ff927edb4f

STIX ID: report--aa3acc2e-b32c-50cd-a159-a1ff927edb4f

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-21

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Grafana Labs disclosed CVE-2025-41115, a maximum-severity vulnerability in Grafana Enterprise affecting versions 12.0.0–12.2.1 when SCIM provisioning and certain feature flags are enabled; a numeric SCIM externalId could be interpreted as an existing internal user ID, allowing impersonation or privilege escalation. Grafana Cloud services were patched ahead of disclosure, Grafana OSS is unaffected, and self-managed instances should upgrade to the provided patched versions or disable SCIM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.