CVE-2025-3580: Medium severity grafana vulnerability
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.
The vulnerability can be exploited when:
1. An Organization administrator exists
2. The Server administrator is either:
- Not part of any organization, or - Part of the same organization as the Organization administrator Impact:
- Organization administrators can permanently delete Server administrator accounts
- If the only Server administrator is deleted, the Grafana instance becomes unmanageable
- No super-user permissions remain in the system
- Affects all users, organizations, and teams managed in the instance
The vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3580?
CVE-2025-3580 has been classified as a high severity access control vulnerability in Grafana OSS.
How do I fix CVE-2025-3580?
To fix CVE-2025-3580, upgrade to the latest version of Grafana OSS where this vulnerability has been addressed.
Who is affected by CVE-2025-3580?
CVE-2025-3580 affects organizations using Grafana OSS where an Organization administrator role is present.
What are the potential impacts of exploiting CVE-2025-3580?
Exploiting CVE-2025-3580 can lead to the permanent deletion of the Server administrator account by an Organization administrator.
How can I identify if I am vulnerable to CVE-2025-3580?
You may be vulnerable to CVE-2025-3580 if your instance of Grafana OSS allows Organization administrators to access the DELETE /api/org/users/ endpoint.