PT-2025-47560 · Grafana · Grafana+1

Published

2025-11-19

·

Updated

2026-03-10

·

CVE-2025-41115

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Grafana versions 12.0.0 through 12.2.1 Grafana versions 12.0.6, 12.1.3, 12.1.4, 12.2.1, and 12.3.0
Description A critical vulnerability exists in Grafana Enterprise versions 12.x related to the System for Cross-domain Identity Management (SCIM) provisioning feature. This flaw allows a malicious or compromised SCIM client to provision a user with a numeric externalId, potentially overriding internal user IDs and leading to impersonation or privilege escalation. The vulnerability is triggered when both the enableSCIM feature flag and the user sync enabled configuration option within the [auth.scim] block are set to true. An attacker can exploit this by sending a crafted SCIM request to the /api/scim/v2/Users endpoint with a manipulated externalId parameter. The vulnerability allows an attacker to gain administrative access. Approximately 601,000 instances are exposed.
Recommendations Update to Grafana Enterprise version 12.0.6 Update to Grafana Enterprise version 12.1.3 Update to Grafana Enterprise version 12.1.4 Update to Grafana Enterprise version 12.2.1 Update to Grafana Enterprise version 12.3.0 If SCIM is not required, disable the enableSCIM feature flag and the user sync enabled configuration option in the [auth.scim] block. Monitor logs and network traffic for suspicious SCIM requests, particularly those with numeric externalId values.

Exploit

Fix

LPE

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2025-14561
BIT-GRAFANA-2025-41115
CVE-2025-41115
ECHO-D885-5D85-11DB
GHSA-W62R-7C53-FMC5
GO-2025-4153
SUSE-SU-2025:4395-1

Affected Products

Grafana
Grafana Enterprise