Critical Grafana Enterprise SCIM Flaw Hits Hosting Providers: Why Staying Updated Matters

Grafana has released a set of emergency security patches after discovering a critical vulnerability in its Enterprise editions. The flaw, tracked as CVE-2025-41115, carries the maximum CVSS score of 10.0 and affects environments where the SCIM feature is enabled and used for automated user provisioning.