vulnerability
Grafana Enterprise: CVE-2025-41115: Authorization Bypass Through User-Controlled Key
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Nov 19, 2025 | Nov 21, 2025 | Nov 21, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Nov 19, 2025
Added
Nov 21, 2025
Modified
Nov 21, 2025
Description
In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling
allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow
to override internal user IDs and lead to impersonation or privilege escalation.
This vulnerability applies only if all of the following conditions are met:
enableSCIM feature flag set to true,
user_sync_enabled config option in the [auth.scim] block set to true.
Solution
grafana-enterprise-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.