CVE-2025-41116
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-11

Last updated on: 2025-11-19

Assigner: Grafana Labs

Description
When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, itΒ  could result inΒ  the wrong user identifier being used, and information for which the viewer is not authorized being returned.Β  This issue affects Grafana Databricks Datasource Plugin: from 1.6.0 before 1.12.0
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-11
Last Modified
2025-11-19
Generated
2026-06-16
AI Q&A
2025-11-11
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
grafana databricks_datasource_plugin 1.6.0
grafana databricks_datasource_plugin 1.12.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability occurs in the Grafana Databricks Datasource Plugin when OAuth passthrough is enabled and multiple users access the same datasource simultaneously on a single Grafana instance. It can cause the wrong user identifier to be used, leading to information being returned to a viewer who is not authorized to see it.

Impact Analysis

The vulnerability can result in unauthorized access to information because the system may return data associated with the wrong user. This means sensitive or private information could be exposed to users who should not have access to it.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-41116. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart