CVE-2025-3580 describes an access control vulnerability in Grafana OSS where an Organization administrator can permanently delete a Server administrator account. This flaw, residing in the DELETE /api/org/users/ endpoint, can lead to a complete loss of administrative control if the sole Server administrator is removed, rendering the Grafana instance unmanageable. Rated as Medium severity (CVSS 5.5), it requires high privileges (an existing Organization administrator) but has low attack complexity, impacting the availability of the system. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.4.18, < 10.4.19CPE match | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.2.9, < 11.2.10CPE match | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.3.6, < 11.3.7CPE match | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.4.4, < 11.4.5CPE match | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.5.4, < 11.5.5CPE match | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
grafana: Improper access control in the /api/org/users/ API endpoint
May 23, 2025Privilege Escalation in Admin Management in Grafana
May 22, 2025Privilege Escalation in Admin Management in Grafana
May 22, 2025Privilege Escalation in Admin Management in Grafana
May 22, 2025Privilege Escalation in Admin Management in Grafana
May 22, 2025Privilege Escalation in Admin Management in Grafana
May 22, 2025Privilege Escalation in Admin Management in Grafana
May 22, 2025