• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

Admin by Admin
November 22, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Nov 21, 2025Ravie LakshmananVulnerability / Menace Mitigation

Grafana has launched safety updates to deal with a most severity safety flaw that would permit privilege escalation or person impersonation beneath sure configurations.

The vulnerability, tracked as CVE-2025-41115, carries a CVSS rating of 10.0. It resides within the System for Cross-domain Id Administration (SCIM) part that permits automated person provisioning and administration. First launched in April 2025, it is presently in public preview.

“In Grafana variations 12.x the place SCIM provisioning is enabled and configured, a vulnerability in person id dealing with permits a malicious or compromised SCIM consumer to provision a person with a numeric externalId, which in flip might permit for overriding inner person IDs and result in impersonation or privilege escalation,” Grafana’s Vardan Torosyan stated.

DFIR Retainer Services

That stated, profitable exploitation hinges on each circumstances being met –

  • enableSCIM function flag is ready to true
  • user_sync_enabled config choice within the [auth.scim] block is ready to true

The shortcoming impacts Grafana Enterprise variations from 12.0.0 to 12.2.1. It has been addressed within the following variations of the software program –

  • Grafana Enterprise 12.0.6+security-01
  • Grafana Enterprise 12.1.3+security-01
  • Grafana Enterprise 12.2.1+security-01
  • Grafana Enterprise 12.3.0

“Grafana maps the SCIM externalId on to the inner person.uid; subsequently, numeric values (e.g. ‘1’) could also be interpreted as inner numeric person IDs,” Torosyan stated. “In particular instances this might permit the newly provisioned person to be handled as an current inner account, such because the Admin, resulting in potential impersonation or privilege escalation.”

The analytics and observability platform stated the vulnerability was found internally on November 4, 2025, throughout an audit and testing. Given the severity of the problem, customers are suggested to use the patches as quickly as doable to mitigate potential dangers.

Tags: CVSSEnablingEscalationFlawGrafanaimpersonationPatchesPrivilegeSCIM
Admin

Admin

Next Post
How this founder’s unlikely path to Silicon Valley may change into an edge in industrial tech

How this founder’s unlikely path to Silicon Valley may change into an edge in industrial tech

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

These 5 Easy Methods Helped Me Construct a Smarter House

These 5 Easy Methods Helped Me Construct a Smarter House

July 19, 2025
Discover a Software program Improvement Firm in Europe

Discover a Software program Improvement Firm in Europe

August 22, 2025
Arbitrage: Environment friendly Reasoning by way of Benefit-Conscious Hypothesis

Arbitrage: Environment friendly Reasoning by way of Benefit-Conscious Hypothesis

August 8, 2026
Consider any agent framework with Amazon Bedrock AgentCore Evaluations

Consider any agent framework with Amazon Bedrock AgentCore Evaluations

August 27, 2026
Submit Your Questions: The Nice Knowledge Heart Backlash

Submit Your Questions: The Nice Knowledge Heart Backlash

August 27, 2026

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Anthropic Discloses Fourth Incident of Claude Breaching Actual Techniques Throughout Safety Checks

Anthropic Discloses Fourth Incident of Claude Breaching Actual Techniques Throughout Safety Checks

September 13, 2026
Your Mannequin Is not Completed Till Somebody Else Can Name It

Your Mannequin Is not Completed Till Somebody Else Can Name It

September 13, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved