logo

How to find Grafana instances on your network

ID: 145218fd-8911-576f-9bb4-6295db50c106

STIX ID: report--145218fd-8911-576f-9bb4-6295db50c106

Feed Name: runZero Blog

Threat Score
75/100

Date Published: 2021-12-08

Date Updated: 2026-04-29

Author: runZero Team

...
...

The report details a critical Grafana Enterprise vulnerability (CVE-2025-41115) in the SCIM component that enables remote, unauthenticated impersonation potentially leading to administrative access for Grafana Enterprise versions 12.0.0 through 12.2.1; Grafana has released patches and the advisory lists recommended upgrade versions and runZero queries to discover affected assets. The document also summarizes an earlier high-severity path traversal (CVE-2021-43798) and recommends updating or mitigating vulnerable Grafana deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.