Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation Emmie Evans November 22, 2025

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

Grafana has released security updates to address a maximum severity security flaw that could allow privilege escalation or user impersonation under certain configurations.
The vulnerability, tracked as CVE-2025-41115, carries a CVSS score of 10.0. It resides in the System for Cross-domain Identity Management (SCIM) component that allows automated user provisioning and management. First

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top