Article Details
Scrape Timestamp (UTC): 2025-11-21 15:41:36.007
Source: https://thehackernews.com/2025/11/grafana-patches-cvss-100-scim-flaw.html
Original Article Text
Click to Toggle View
Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation. Grafana has released security updates to address a maximum severity security flaw that could allow privilege escalation or user impersonation under certain configurations. The vulnerability, tracked as CVE-2025-41115, carries a CVSS score of 10.0. It resides in the System for Cross-domain Identity Management (SCIM) component that allows automated user provisioning and management. First introduced in April 2025, it's currently in public preview. "In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow for overriding internal user IDs and lead to impersonation or privilege escalation," Grafana's Vardan Torosyan said. That said, successful exploitation hinges on both conditions being met - The shortcoming affects Grafana Enterprise versions from 12.0.0 to 12.2.1. It has been addressed in the following versions of the software - "Grafana maps the SCIM externalId directly to the internal user.uid; therefore, numeric values (e.g. '1') may be interpreted as internal numeric user IDs," Torosyan said. "In specific cases this could allow the newly provisioned user to be treated as an existing internal account, such as the Admin, leading to potential impersonation or privilege escalation." The analytics and observability platform said the vulnerability was discovered internally on November 4, 2025, during an audit and testing. Given the severity of the issue, users are advised to apply the patches as soon as possible to mitigate potential risks.
Daily Brief Summary
Grafana has issued patches to fix a critical vulnerability in its SCIM component, identified as CVE-2025-41115, which could lead to privilege escalation or user impersonation.
The flaw, scoring a maximum CVSS of 10.0, affects Grafana Enterprise versions 12.0.0 to 12.2.1 where SCIM provisioning is enabled and configured.
Exploitation occurs when a malicious SCIM client provisions a user with a numeric externalId, potentially overriding internal user IDs.
This vulnerability was discovered internally by Grafana on November 4, 2025, during routine audits and testing of their systems.
Grafana urges users to apply the released patches immediately to prevent exploitation, given the high severity and potential impact.
The issue stems from the SCIM externalId mapping directly to internal user IDs, which can lead to impersonation of critical accounts like Admin.
Organizations using affected versions should review their SCIM configurations and update to the patched versions to secure their environments.