Grafana Security Updates – 23 November 2025

Grafana has released security updates to fix several vulnerabilities, including a critical vulnerability in Grafana Enterprise.

The addressed vulnerabilities could allow the attacker to provision a user with a numeric external IDs, which may override internal user IDs and result in impersonation or privilege escalation.

Sample of the addressed vulnerabilities:

Grafana Enterprise Incorrect Privilege Assignment Vulnerability (CVE-2025- 41115):

  • CVSS: 10.0
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Privilege Escalation

The affected products:

  • Grafana Enterprise.
  • Grafana Databricks Datasource Plugin.
  • Grafana Snowflake Datasource Plugin.
Vulnerabilities
  • CVE-2025-41115
  • CVE-2025-41116
  • CVE-2025-3717
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Grafana Security Advisory

References