• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

Admin by Admin
November 22, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Nov 21, 2025Ravie LakshmananVulnerability / Menace Mitigation

Grafana has launched safety updates to deal with a most severity safety flaw that would permit privilege escalation or person impersonation beneath sure configurations.

The vulnerability, tracked as CVE-2025-41115, carries a CVSS rating of 10.0. It resides within the System for Cross-domain Id Administration (SCIM) part that permits automated person provisioning and administration. First launched in April 2025, it is presently in public preview.

“In Grafana variations 12.x the place SCIM provisioning is enabled and configured, a vulnerability in person id dealing with permits a malicious or compromised SCIM consumer to provision a person with a numeric externalId, which in flip might permit for overriding inner person IDs and result in impersonation or privilege escalation,” Grafana’s Vardan Torosyan stated.

DFIR Retainer Services

That stated, profitable exploitation hinges on each circumstances being met –

  • enableSCIM function flag is ready to true
  • user_sync_enabled config choice within the [auth.scim] block is ready to true

The shortcoming impacts Grafana Enterprise variations from 12.0.0 to 12.2.1. It has been addressed within the following variations of the software program –

  • Grafana Enterprise 12.0.6+security-01
  • Grafana Enterprise 12.1.3+security-01
  • Grafana Enterprise 12.2.1+security-01
  • Grafana Enterprise 12.3.0

“Grafana maps the SCIM externalId on to the inner person.uid; subsequently, numeric values (e.g. ‘1’) could also be interpreted as inner numeric person IDs,” Torosyan stated. “In particular instances this might permit the newly provisioned person to be handled as an current inner account, such because the Admin, resulting in potential impersonation or privilege escalation.”

The analytics and observability platform stated the vulnerability was found internally on November 4, 2025, throughout an audit and testing. Given the severity of the problem, customers are suggested to use the patches as quickly as doable to mitigate potential dangers.

Tags: CVSSEnablingEscalationFlawGrafanaimpersonationPatchesPrivilegeSCIM
Admin

Admin

Next Post
How this founder’s unlikely path to Silicon Valley may change into an edge in industrial tech

How this founder’s unlikely path to Silicon Valley may change into an edge in industrial tech

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Information transient: Nation-state threats evolve and escalate

Information transient: Nation-state threats evolve and escalate

October 31, 2025
OpenAI Warns GPT-5.6 File Deletions Stem From Full Entry Mode

OpenAI Warns GPT-5.6 File Deletions Stem From Full Entry Mode

July 17, 2026
Ex-Activision Boss Bobby Kotick Needs To Purchase TikTok

Ex-Activision Boss Bobby Kotick Needs To Purchase TikTok

May 18, 2025
Tomba! 2: The Evil Swine Return Particular Version Evaluation

Tomba! 2: The Evil Swine Return Particular Version Evaluation

December 15, 2025
These 5 Easy Methods Helped Me Construct a Smarter House

These 5 Easy Methods Helped Me Construct a Smarter House

July 19, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Samsung’s SmartThings API Terminates Free Entry

July 29, 2026
Safety Cannot Be an Afterthought as AI Brokers Reshape DevOps

Safety Cannot Be an Afterthought as AI Brokers Reshape DevOps

July 29, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved