{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-3580","assignerOrgId":"57da9224-a3e2-4646-9d0e-c4dc2e05e7da","state":"PUBLISHED","assignerShortName":"GRAFANA","dateReserved":"2025-04-14T10:36:24.956Z","datePublished":"2025-05-23T13:44:45.974Z","dateUpdated":"2025-07-17T10:28:18.011Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Grafana","vendor":"Grafana","versions":[{"lessThan":"12.0.1","status":"affected","version":"12.0.0","versionType":"semver"},{"lessThan":"11.6.2","status":"affected","version":"11.6.1","versionType":"semver"},{"lessThan":"11.5.5","status":"affected","version":"11.5.4","versionType":"semver"},{"lessThan":"11.4.5","status":"affected","version":"11.4.4","versionType":"semver"},{"lessThan":"11.3.7","status":"affected","version":"11.3.6","versionType":"semver"},{"lessThan":"11.2.10","status":"affected","version":"11.2.9","versionType":"semver"},{"lessThan":"10.4.19","status":"affected","version":"10.4.18","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Saket Pandey"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.</p><p>The vulnerability can be exploited when:</p><p>1. An Organization administrator exists</p><p>2. The Server administrator is either:</p><code>   - Not part of any organization, or</code><br><code>   - Part of the same organization as the Organization administrator</code><br><p>Impact:</p><p>- Organization administrators can permanently delete Server administrator accounts</p><p>- If the only Server administrator is deleted, the Grafana instance becomes unmanageable</p><p>- No super-user permissions remain in the system</p><p>- Affects all users, organizations, and teams managed in the instance</p><p>The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.</p>"}],"value":"An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.\n\nThe vulnerability can be exploited when:\n\n1. An Organization administrator exists\n\n2. The Server administrator is either:\n\n   - Not part of any organization, or\n   - Part of the same organization as the Organization administrator\nImpact:\n\n- Organization administrators can permanently delete Server administrator accounts\n\n- If the only Server administrator is deleted, the Grafana instance becomes unmanageable\n\n- No super-user permissions remain in the system\n\n- Affects all users, organizations, and teams managed in the instance\n\nThe vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance."}],"impacts":[{"capecId":"CAPEC-180","descriptions":[{"lang":"en","value":"CAPEC-180"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"57da9224-a3e2-4646-9d0e-c4dc2e05e7da","shortName":"GRAFANA","dateUpdated":"2025-07-17T10:28:18.011Z"},"references":[{"tags":["vendor-advisory"],"url":"https://grafana.com/security/security-advisories/cve-2025-3580/"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-05-23T14:04:27.385036Z","id":"CVE-2025-3580","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-05-23T14:05:09.480Z"}}]}}