vulnerability

Grafana Enterprise: CVE-2025-41115: Authorization Bypass Through User-Controlled Key

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Nov 19, 2025
Added
Nov 21, 2025
Modified
Nov 21, 2025

Description

In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling
allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow
to override internal user IDs and lead to impersonation or privilege escalation.
This vulnerability applies only if all of the following conditions are met:
enableSCIM feature flag set to true,
user_sync_enabled config option in the [auth.scim] block set to true.

Solution

grafana-enterprise-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.