Privilege Escalation Vulnerability in Volkov Labs Business Links for Grafana
CVE-2025-58746

9.1CRITICAL

Key Information:

Vendor

Volkovlabs

Vendor
CVE Published:
8 September 2025

What is CVE-2025-58746?

The Volkov Labs Business Links plugin for Grafana has a vulnerability where users with Editor privileges can escalate their access to Administrator levels. This security flaw arises from the ability to inject arbitrary JavaScript code in the plugin’s URL field, allowing malicious actors to perform unauthorized administrative actions. The issue has been addressed in version 2.4.0, which includes a fix for the vulnerability, ensuring enhanced security for Grafana users.

Affected Version(s)

business-links < 2.4.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.