Access Control Flaw in Grafana OSS Affects Organizational Administrators
CVE-2025-3580
5.5MEDIUM
What is CVE-2025-3580?
An access control vulnerability in Grafana OSS allows an Organization administrator to permanently delete the Server administrator account via the DELETE /api/org/users/ endpoint. This issue arises when an Organization administrator can exploit their privileges, especially when the Server administrator is either not linked to any organization or belongs to the same organization. The impact is critical as it enables the deletion of Server administrator accounts, leading to the impossibility of managing the Grafana instance. This results in a loss of control over all users, organizations, and teams in the system, making the Grafana instance unmanageable.
Affected Version(s)
Grafana 12.0.0 < 12.0.1
Grafana 11.6.1 < 11.6.2
Grafana 11.5.4 < 11.5.5