Grafana 12.0.0-12.2.0 - Privilege Escalation via SCIM User Provisioning
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-41115. PoCs published by I3r1h0n, rockmelodies.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-41115, targeting Grafana Enterprise's SCIM provisioning component. The exploit leverages improper user ID handling to achieve privilege escalation by overriding internal user IDs.
Description
SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow to override internal user IDs and lead to impersonation or privilege escalation. This vulnerability applies only if all of the following conditions are met: - `enableSCIM` feature flag set to true - `user_sync_enabled` config option in the `[auth.scim]` block set to true
Exploits (2)
This repository contains a functional exploit for CVE-2025-41115, targeting Grafana Enterprise's SCIM provisioning component. The exploit leverages improper user ID handling to achieve privilege escalation by overriding internal user IDs.
This PoC exploits CVE-2025-41115, a critical privilege escalation vulnerability in Grafana Enterprise's SCIM user-provisioning feature. It allows an attacker to overwrite existing user accounts, including admins, by sending a numeric `externalId` in a SCIM request.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H