CVE Details
Basic Information
| Title | CVE-2025-3580 |
|---|---|
| Type | cve |
| Published | 2025-05-23T13:44:45 |
| Last Seen | 2025-05-23T14:28:12 |
CVSS Information
| Base Score | 5.5 (MEDIUM) |
|---|---|
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | LOW |
| Availability Impact | HIGH |
AI Analysis
| AI Description | An access control vulnerability in Grafana OSS allows an Organization administrator to permanently delete the Server administrator account via the DELETE /api/org/users/ endpoint. This can lead to a denial of service and potential loss of administrative control. |
|---|---|
| AI Severity | Medium |
| Vendor | Grafana Labs |
| Product | Grafana OSS |
| Affected Version |
Additional Information
| CVE List | CVE-2025-3580 |
|---|---|
| CWE List | CWE-284 |
| Bulletin Family | cve |
Description
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can…
CVSS Score Summary
Base Score: %!f(string=#) (MEDIUM)