Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-41115

44
FAUCET Score

CVE-2025-41115 is a critical vulnerability affecting Grafana Enterprise and Grafana Cloud versions 12.x when SCIM provisioning is enabled and configured. A malicious or compromised SCIM client can provision a user with a numeric externalId, potentially overriding internal user IDs and leading to impersonation or privilege escalation. This vulnerability has a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.

Impacted Technologies

VendorProductVersion(s)CPE
>= 12.0.0, < 12.2.1CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
16.91%
Probability of exploitation in next 30 days
EPSS Percentile
96.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1691 is in the 93rd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 12.0.7
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 12.1.4
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 12.2.2
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 1.9.2-0.20251106142618-ca5d89812015
nodejspatch availablevia llm_extracted
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

redhatCVE-2025-41115Critical

grafana: Incorrect Privilege Assignment

Nov 25, 2025
goGHSA-w62r-7c53-fmc5critical

Grafana Incorrect Privilege Assignment vulnerability

Nov 21, 2025
kenticollm-kentico-4b02004c7145bc8cCRITICAL

Incorrect privilege assignment

Nov 19, 2025
chainsafellm-chainsafe-c4708338b9e2422bCRITICAL

Incorrect privilege assignment

Nov 19, 2025
apollographqlllm-apollographql-2ae15e87393d91b7CRITICAL

Incorrect privilege assignment

Nov 19, 2025
jenkinsllm-jenkins-a06c5eed904411c8CRITICAL

Incorrect privilege assignment

Nov 19, 2025
nodejsllm-nodejs-739b9530b3c77b20CRITICAL

Incorrect privilege assignment

Nov 19, 2025
zimbrallm-zimbra-d5a50b51d0da0c15CRITICAL

Incorrect privilege assignment

Nov 19, 2025

References

grafana.com / security/security-advisories/cve-2025-41115
Broken Link