
Exploit and test stand for CVE-2025-41115
This repo is my research on CVE-2025-41115 vulnerability in Grafana Enterprise SCIM component. It consist of a test stand with vulnerable app and exploit code.
Just some usefull refs:
secirutvulnerability.ioSCIM provisioning works for Grafana Enterprise and Grafana Cloud only.
In Grafana versions 12.x+, where SCIM provisioning is configured, a security flaw in user identity management. This can potentially allow for the overriding of internal user IDs, leading to impersonation or privilege escalation.
The bug exists only if this configured:
enableSCIM feature flag is set.user_sync_enabled is set.Look at this commit to see the fixes applied. It adds an extra checks preventing the id collisions.
If you want to dig deeper into the SCIM security flaws, I strongly recommend you this article from Doyensec. It describes the concept of SCIM and guides you thought typical security issues.
The stand requires a valid Grafana Enterprise license key. Without it, the SCIM enabling config values will be ignored. Past you key to ./stand/license.jwt.
After this, just run:
docker compose up -d
This will pull and spin up a vulnerable Grafana.
After grafana starts, run the ./stand/init.sh. This will create a service account and get a token for it. It will print the token.
Just past the token to ./exploit/resource/config.toml. Change the config values if needed.
After just run the:
cd exploit
uv run src/main.py
Happy pwning!
prod by I3r1h0n.