Grafana Vulnerability Disclosure: SCIM Flaw Could Lead to Privilege Escalation

The discovery of CVE-2025-41115 exposes a critical security weakness in the Grafana Enterprise SCIM (System for Cross-domain Identity Management) component, enabling attackers to escalate privileges or impersonate existing users under specific configuration conditions. This flaw poses a significant threat to organizations relying on SCIM for automated identity provisioning and user lifecycle management. Vulnerability Details Privilege […]

The post Grafana Vulnerability Disclosure: SCIM Flaw Could Lead to Privilege Escalation appeared first on SecPod Blog.