Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Mesa closes credit card that rewards cardholders for mortgage payments

Understanding the risky Netflix and Warner Bros. deal

History of Science: Norwegian explorer wins perilous race to the South Pole while British rival dies along with his crew — December 14, 1911

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Grafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation
Identity

Grafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation

userBy userNovember 21, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 21, 2025Rabi LakshmananVulnerability/Threat Mitigation

Grafana has released a security update to address a maximum severity security flaw that could allow privilege escalation and user impersonation under certain configurations.

This vulnerability is tracked as CVE-2025-41115 and has a CVSS score of 10.0. It resides within the System for Cross-Domain Identity Management (SCIM) component, which enables automated user provisioning and management. It was first introduced in April 2025 and is currently in public preview.

“In Grafana version 12.x with SCIM provisioning enabled and configured, a vulnerability in user ID handling could allow a malicious or compromised SCIM client to provision a user with a numeric externalId, which could override the internal user ID and potentially lead to impersonation and privilege escalation,” said Vardan Torosyan of Grafana.

DFIR retainer service

However, a successful exploit depends on whether both conditions are met.

user_sync_enabled configuration option with the EnableSCIM feature flag set to true [auth.scim] block is set to true

This drawback affects Grafana Enterprise versions 12.0.0 to 12.2.1. This issue is resolved in the following versions of the software.

Grafana Enterprise 12.0.6+security-01 Grafana Enterprise 12.1.3+security-01 Grafana Enterprise 12.2.1+security-01 Grafana Enterprise 12.3.0

“Grafana maps SCIM externalId directly to internal user.uid, so a number (e.g. ‘1’) can be interpreted as an internal numeric user ID,” Torosyan said. “In certain cases, this could result in newly provisioned users being treated as existing internal accounts, such as administrators, which could lead to impersonation and privilege escalation.”

According to the analysis and observation platform, the vulnerability was discovered internally on November 4, 2025 during audit and testing. Given the severity of the issue, we recommend that users apply the patch as soon as possible to reduce potential risks.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSpaceX’s upgraded Starship suffers from explosion during test
Next Article Google says hackers stole data from 200 companies after Gainsight breach
user
  • Website

Related Posts

CISA adds actively exploited flaw in Sierra wireless routers that enables RCE attacks

December 13, 2025

Apple issues security update after two WebKit flaws found to have been exploited

December 13, 2025

Fake OSINT and GPT utility GitHub repositories spread PyStoreRAT malware payload

December 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Mesa closes credit card that rewards cardholders for mortgage payments

Understanding the risky Netflix and Warner Bros. deal

History of Science: Norwegian explorer wins perilous race to the South Pole while British rival dies along with his crew — December 14, 1911

India’s Spinney plans to raise $160 million to buy Go Mechanic, sources say

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.