Grafana Labs announced the discovery of an extremely serious vulnerability in Grafana Enterprise, which opens the way to privilege escalation and possible user impersonation. The issue affects the enterprise version only and was rated CVSS 10.0, which means it is one of the most dangerous vulnerabilities of 2025.

The vulnerability “CVE-2025-41115” and how it arises
The flaw is located in the SCIM (System for Cross-domain Identity Management), which was added to the platform in April 2025 to facilitate identity management and user lifecycle automation.
versions 12.0.0 to 12.2.1 are vulnerable to this vulnerability, where SCIM setup is enabled and configured.
See also: Broadcom: Cl0p breach via zero-day in Oracle EBS?
According to the Grafana Labs team, the vulnerability is caused by incorrect handling of user identities. A malicious SCIM client—or a compromised legitimate client—can send a numeric external ID that can override the internal user IDs used by Grafana.
Simply put: the system can mistake an attacker for an existing user, even an administrator, opening the way for complete control of dashboards, settings, credentials, and interfaces.
Who does it affect and under what conditions?
The vulnerability is only triggered in environments where:
- the enableSCIM flag is set to true
- the configuration option user_sync_enabled is also true
Grafana clarifies that the vulnerability does not affect Grafana OSS users, which limits exposure but does not reduce the severity for organizations that rely on the enterprise version for critical workloads.

Attackers who exploited the vulnerability could gain access to:
- systems monitoring data
- connected service credentials
- dashboards and alerts settings
- tokens often used for automated tasks
See also: Fortinet: 'Silent' patch for second zero-day vulnerability
The discovery and internal mobilization of Grafana Labs
The vulnerability was identified on November 4, 2025 as part of an internal security audit. The company immediately activated incident management procedures and proceeded with a detailed impact assessment.
Grafana Labs emphasizes that no exploit incidents occurred in Grafana Cloud, while no managed environments (e.g. Amazon Managed Grafana and Azure Managed Grafana) were left exposed, as providers automatically pushed the necessary updates.
Fixes are available – What organizations should do
Once the issue was identified, the company's development team released patches within a few days. Affected organizations are urged to immediately upgrade to one of the following secure versions:
- Grafana Enterprise 12.3.0
- 12.2.1 (corrected revision)
- 12.1.3
- 12.0.6
Managed service users on AWS and Azure have already received automatic updates, without any action required.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What the incident means for the security of the surveillance ecosystem
The CVE-2025-41115 case comes at a time when observability platforms—Grafana, Kibana, Datadog, Splunk—are critical nodes for monitoring in organizations operating in cloud-native environments, Kubernetes clusters, and microservices.
See also: Critical vulnerability in Windows Graphics Component

If an attacker gains admin rights on such a system:
- It can hide signs of tampering.
- To bypass security alert systems.
- To access connected services.
- Monitor operational performance in real time — a valuable asset for APT or ransomware groups.
Experts point out that monitoring platforms often act as “hidden one-way streets” in critical environments and do not receive the attention given to identity systems or application servers, making such vulnerabilities even more dangerous.
Strengthening defense: recommended practices
To reduce the risk of similar incidents in the future, the following are recommended:
- Strict management and control of SCIM clients.
- Use least-privilege in integration tokens.
- Monitoring logs for anomalies in user sync events.
- Regular inspection of identity settings and flags that enable advanced features.
Grafana Labs assures that it continues to conduct intensive audits and strengthen protection systems, but the incident is yet another reminder that even leading monitoring platforms can become easy prey when identity components are vulnerable.
