Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-3580

18
FAUCET Score

CVE-2025-3580 describes an access control vulnerability in Grafana OSS where an Organization administrator can permanently delete a Server administrator account. This flaw, residing in the DELETE /api/org/users/ endpoint, can lead to a complete loss of administrative control if the sole Server administrator is removed, rendering the Grafana instance unmanageable. Rated as Medium severity (CVSS 5.5), it requires high privileges (an existing Organization administrator) but has low attack complexity, impacting the availability of the system. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.4.18, < 10.4.19CPE match
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 11.2.9, < 11.2.10CPE match
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 11.3.6, < 11.3.7CPE match
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 11.4.4, < 11.4.5CPE match
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 11.5.4, < 11.5.5CPE match
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 27th percentile among its peer group of 3,565 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

nodejspatch availablevia llm_extracted
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
zimbravendor investigatingvia llm_extracted
View patch

Vendor Advisories (7)

redhatCVE-2025-3580Moderate

grafana: Improper access control in the /api/org/users/ API endpoint

May 23, 2025
zimbrallm-zimbra-a0c6b7862086325fMEDIUM

Privilege Escalation in Admin Management in Grafana

May 22, 2025
kenticollm-kentico-72257c27d806646aMEDIUM

Privilege Escalation in Admin Management in Grafana

May 22, 2025
chainsafellm-chainsafe-155f1364172ef6c3MEDIUM

Privilege Escalation in Admin Management in Grafana

May 22, 2025
apollographqlllm-apollographql-460df74cdf309f8bMEDIUM

Privilege Escalation in Admin Management in Grafana

May 22, 2025
jenkinsllm-jenkins-20fb89743182a95fMEDIUM

Privilege Escalation in Admin Management in Grafana

May 22, 2025
nodejsllm-nodejs-3db5eea2b63e2eacMEDIUM

Privilege Escalation in Admin Management in Grafana

May 22, 2025

References

grafana.com / security/security-advisories/cve-2025-3580