Grafana has addressed a critical security vulnerability (CVE-2025-41115) in its Enterprise platform, specifically affecting the System for Cross-domain Identity Management (SCIM) component. The flaw, rated with a maximum CVSS score of 10.0, allows a malicious or compromised SCIM client to provision users with numeric external IDs, potentially overriding internal user IDs and enabling privilege escalation or user impersonation. Exploitation requires both the enableSCIM feature flag and the user_sync_enabled configuration to be set to true. The vulnerability impacts Grafana Enterprise versions 12.0.0 to 12.2.1 and has been resolved in versions 12.0.6+security-01, 12.1.3+security-01, 12.2.1+security-01, and 12.3.0.
The issue was discovered internally by Grafana during an audit on November 4, 2025, and prompted immediate patch releases due to its severity. Security advisories from multiple sources urge administrators to apply the updates promptly to mitigate the risk of privilege escalation and user impersonation attacks. Organizations using affected versions with SCIM provisioning enabled are strongly advised to review their configurations and update to the patched releases without delay.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Grafana later warned that mismatches between SCIM externalId values and SAML identity attributes can cause account-linking failures and enable unauthorized access or impersonation scenarios related to CVE-2025-41115. The company recommended aligning SCIM and SAML on the same stable identity attribute and configuring assertion_attribute_external_uid appropriately.
On November 21, 2025, the Canadian Centre for Cyber Security published advisory AV25-778 highlighting Grafana's November 19 security advisory. It urged administrators to review the vendor guidance and apply the necessary updates.
On November 19, 2025, Grafana publicly disclosed CVE-2025-41115 and released security updates for affected Grafana Enterprise versions, including 12.3.0, 12.2.1, 12.1.3, and 12.0.6 and related security builds. The flaw affects SCIM-enabled Enterprise deployments and can enable user impersonation or privilege escalation.
Before public disclosure, Grafana patched Grafana Cloud as well as Amazon Managed Grafana and Azure Managed Grafana. During its investigation, the company said it found no evidence of exploitation in Grafana Cloud.
According to Grafana, a fix for CVE-2025-41115 was introduced roughly 24 hours after the issue was discovered internally. This remediation preceded the public advisory and release of patched versions.
Grafana said it identified the maximum-severity SCIM flaw CVE-2025-41115 on November 4, 2025 during internal audit and testing. The bug could let a malicious or compromised SCIM client impersonate users or escalate privileges in affected Enterprise deployments.
Grafana's SCIM provisioning component, later found to contain CVE-2025-41115, was introduced in April 2025 as a public preview feature in Grafana Enterprise 12.x.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcerunzero.com
Open sourcethehackernews.com
Open sourcecyber.gc.ca
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.