By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation
Tech News

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

By Viral Trending Content 2 Min Read
Share
SHARE

Nov 21, 2025Ravie LakshmananVulnerability / Threat Mitigation

Grafana has released security updates to address a maximum severity security flaw that could allow privilege escalation or user impersonation under certain configurations.

The vulnerability, tracked as CVE-2025-41115, carries a CVSS score of 10.0. It resides in the System for Cross-domain Identity Management (SCIM) component that allows automated user provisioning and management. First introduced in April 2025, it’s currently in public preview.

“In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow for overriding internal user IDs and lead to impersonation or privilege escalation,” Grafana’s Vardan Torosyan said.

DFIR Retainer Services

That said, successful exploitation hinges on both conditions being met –

  • enableSCIM feature flag is set to true
  • user_sync_enabled config option in the [auth.scim] block is set to true

The shortcoming affects Grafana Enterprise versions from 12.0.0 to 12.2.1. It has been addressed in the following versions of the software –

  • Grafana Enterprise 12.0.6+security-01
  • Grafana Enterprise 12.1.3+security-01
  • Grafana Enterprise 12.2.1+security-01
  • Grafana Enterprise 12.3.0

“Grafana maps the SCIM externalId directly to the internal user.uid; therefore, numeric values (e.g. ‘1’) may be interpreted as internal numeric user IDs,” Torosyan said. “In specific cases this could allow the newly provisioned user to be treated as an existing internal account, such as the Admin, leading to potential impersonation or privilege escalation.”

The analytics and observability platform said the vulnerability was discovered internally on November 4, 2025, during an audit and testing. Given the severity of the issue, users are advised to apply the patches as soon as possible to mitigate potential risks.

You Might Also Like

AirTags Black Friday Discount: Buy for £26/$18

AI One Raises $11M to Help Companies Turn Business Context Into Decision-Ready AI

Alienware Aurora Gaming Desktop Review: Great Value

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

What opportunities exist for experts in Ireland’s offshore wind sector?

TAGGED: Cyber Security, Cybersecurity, Identity Management, Internet, Patch Management, Threat Mitigation, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article European Commission challenges Italy over ‘golden power’ on mergers
Next Article Why sycophantic AI tools are holding businesses back
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Cyprus to join Schengen Zone in 2026: What travellers need to know
World News
Another Senator Co-Sponsors Bill Against Forced Organ Harvesting in China
Politics
AirTags Black Friday Discount: Buy for £26/$18
Tech News
‘Tremendous progress’ in US efforts to end Russia – Ukraine war, Trump says
World News
U.S. consumers dial back in sign of anxiety heading Into holidays
Business
A fun Premier League weekend + a bit of re-watching
Sports
Monad (MON) soars 76% as mainnet launch sparks $1.2B trading surge
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Cyprus to join Schengen Zone in 2026: What travellers need to know

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Cyprus to join Schengen Zone in 2026: What travellers need to know
November 25, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?