Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
GrafanaSCIMalform — Exploit and test stand for CVE-2025-41115 | Kitploit
Tools/GitHubGitHub/i3r1h0n/grafanascimalform
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubi3r1h0n/grafanascimalform

GrafanaSCIMalform

Exploit and test stand for CVE-2025-41115

View Repository
10 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Grafana SCIMalform (CVE-2025-41115)

Overview

This repo is my research on CVE-2025-41115 vulnerability in Grafana Enterprise SCIM component. It consist of a test stand with vulnerable app and exploit code.

References

Just some usefull refs:

  • NIST - NIST index
  • Grafana Article - Original blog post
  • Gitlab - GitLab advisory
  • Securityvulnerability.io - Vuln page on secirutvulnerability.io

Root cause

SCIM provisioning works for Grafana Enterprise and Grafana Cloud only.

In Grafana versions 12.x+, where SCIM provisioning is configured, a security flaw in user identity management. This can potentially allow for the overriding of internal user IDs, leading to impersonation or privilege escalation.

The bug exists only if this configured:

  • enableSCIM feature flag is set.
  • user_sync_enabled is set.

Look at this commit to see the fixes applied. It adds an extra checks preventing the id collisions.

If you want to dig deeper into the SCIM security flaws, I strongly recommend you this article from Doyensec. It describes the concept of SCIM and guides you thought typical security issues.

Stand

The stand requires a valid Grafana Enterprise license key. Without it, the SCIM enabling config values will be ignored. Past you key to ./stand/license.jwt.

After this, just run:

docker compose up -d

This will pull and spin up a vulnerable Grafana.

After grafana starts, run the ./stand/init.sh. This will create a service account and get a token for it. It will print the token.

Exploitation

Just past the token to ./exploit/resource/config.toml. Change the config values if needed.

After just run the:

cd exploit
uv run src/main.py

Happy pwning!

Creds

prod by I3r1h0n.

Download Tool