« Volver al listado

CVE-2025-3580

Estado: AplazadaMedia (5.5)—

An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.

The vulnerability can be exploited when:

1. An Organization administrator exists

2. The Server administrator is either:

- Organization administrators can permanently delete Server administrator accounts

- If the only Server administrator is deleted, the Grafana instance becomes unmanageable

- No super-user permissions remain in the system

- Affects all users, organizations, and teams managed in the instance

Leer descripción completaMostrar menos

The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.

Detalles técnicos trazas, registros y código del informe original
   - Not part of any organization, or
   - Part of the same organization as the Organization administrator
Impact:

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-3580",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-3580",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-23T14:04:27.385036Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@grafana.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@grafana.com",
      "affectedData": [
        {
          "vendor": "Grafana",
          "product": "Grafana",
          "versions": [
            {
              "status": "affected",
              "version": "12.0.0",
              "lessThan": "12.0.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.6.1",
              "lessThan": "11.6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.5.4",
              "lessThan": "11.5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.4.4",
              "lessThan": "11.4.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.3.6",
              "lessThan": "11.3.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.2.9",
              "lessThan": "11.2.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.4.18",
              "lessThan": "10.4.19",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-23T14:15:28.740",
  "references": [
    {
      "url": "https://grafana.com/security/security-advisories/cve-2025-3580/",
      "source": "security@grafana.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@grafana.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.\n\nThe vulnerability can be exploited when:\n\n1. An Organization administrator exists\n\n2. The Server administrator is either:\n\n   - Not part of any organization, or\n   - Part of the same organization as the Organization administrator\nImpact:\n\n- Organization administrators can permanently delete Server administrator accounts\n\n- If the only Server administrator is deleted, the Grafana instance becomes unmanageable\n\n- No super-user permissions remain in the system\n\n- Affects all users, organizations, and teams managed in the instance\n\nThe vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance."
    },
    {
      "lang": "es",
      "value": "Se descubrió una vulnerabilidad de control de acceso en Grafana OSS donde un administrador de la organización podría eliminar permanentemente la cuenta del administrador del servidor. Esta vulnerabilidad existe en el endpoint DELETE /api/org/users/. La vulnerabilidad se puede explotar cuando: 1. Existe un administrador de la organización 2. El administrador del servidor es: - No forma parte de ninguna organización, o - Forma parte de la misma organización que el administrador de la organización Impacto: - Los administradores de la organización pueden eliminar permanentemente las cuentas del administrador del servidor - Si se elimina el único administrador del servidor, la instancia de Grafana se vuelve inadministrable - No quedan permisos de superusuario en el sistema - Afecta a todos los usuarios, organizaciones y equipos administrados en la instancia La vulnerabilidad es particularmente grave, ya que puede llevar a una pérdida total del control administrativo sobre la instancia de Grafana."
    }
  ],
  "lastModified": "2026-06-17T09:20:14.250",
  "sourceIdentifier": "security@grafana.com"
}