Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Megan Thee Stallion, David Guetta and EJAE share FIFA World Cup song ‘DNA’

Mouse On Mars Talk Makes Lee Scratch Perry’s Final Project: Interview

Amy Adams wears a little black dress on ‘Late Night’

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Grafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation
Celebrities

Grafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation

By November 21, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 21, 2025Rabi LakshmananVulnerability/Threat Mitigation

Grafana has released a security update to address a maximum severity security flaw that could allow privilege escalation and user impersonation under certain configurations.

This vulnerability is tracked as CVE-2025-41115 and has a CVSS score of 10.0. It resides within the System for Cross-Domain Identity Management (SCIM) component, which enables automated user provisioning and management. It was first introduced in April 2025 and is currently in public preview.

“In Grafana version 12.x with SCIM provisioning enabled and configured, a vulnerability in user ID handling could allow a malicious or compromised SCIM client to provision a user with a numeric externalId, which could override the internal user ID and potentially lead to impersonation and privilege escalation,” said Vardan Torosyan of Grafana.

DFIR retainer service

However, a successful exploit depends on whether both conditions are met.

user_sync_enabled configuration option with the EnableSCIM feature flag set to true [auth.scim] block is set to true

This drawback affects Grafana Enterprise versions 12.0.0 to 12.2.1. This issue is resolved in the following versions of the software.

Grafana Enterprise 12.0.6+security-01 Grafana Enterprise 12.1.3+security-01 Grafana Enterprise 12.2.1+security-01 Grafana Enterprise 12.3.0

“Grafana maps SCIM externalId directly to internal user.uid, so a number (e.g. ‘1’) can be interpreted as an internal numeric user ID,” Torosyan said. “In certain cases, this could result in newly provisioned users being treated as existing internal accounts, such as administrators, which could lead to impersonation and privilege escalation.”

According to the analysis and observation platform, the vulnerability was discovered internally on November 4, 2025 during audit and testing. Given the severity of the issue, we recommend that users apply the patch as soon as possible to reduce potential risks.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSpaceX’s upgraded Starship suffers from explosion during test
Next Article Google says hackers stole data from 200 companies after Gainsight breach

Related Posts

Amy Adams wears a little black dress on ‘Late Night’

June 10, 2026

Queen Camilla adorns Fiona Claire’s feathers for London outing

June 10, 2026

Taylor Swift’s beauty at the ‘Toy Story 5’ premiere

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Megan Thee Stallion, David Guetta and EJAE share FIFA World Cup song ‘DNA’

Mouse On Mars Talk Makes Lee Scratch Perry’s Final Project: Interview

Amy Adams wears a little black dress on ‘Late Night’

Early Prime Day Air Fryer Sale: Shop Instant Pot, Ninja, and more

Trending Posts

Megan Thee Stallion, David Guetta and EJAE share FIFA World Cup song ‘DNA’

June 10, 2026

Mouse On Mars Talk Makes Lee Scratch Perry’s Final Project: Interview

June 10, 2026

Amy Adams wears a little black dress on ‘Late Night’

June 10, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.