Access Control Flaw in Grafana OSS Affects Organizational Administrators
CVE-2025-3580

5.5MEDIUM

Key Information:

Vendor

Grafana

Status
Vendor
CVE Published:
23 May 2025

What is CVE-2025-3580?

An access control vulnerability in Grafana OSS allows an Organization administrator to permanently delete the Server administrator account via the DELETE /api/org/users/ endpoint. This issue arises when an Organization administrator can exploit their privileges, especially when the Server administrator is either not linked to any organization or belongs to the same organization. The impact is critical as it enables the deletion of Server administrator accounts, leading to the impossibility of managing the Grafana instance. This results in a loss of control over all users, organizations, and teams in the system, making the Grafana instance unmanageable.

Affected Version(s)

Grafana 12.0.0 < 12.0.1

Grafana 11.6.1 < 11.6.2

Grafana 11.5.4 < 11.5.5

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.