CVE-2025-6197: Grafana

Medium severity, CVSS 4.2. EPSS: 74% chance of exploitation in the next 30 days.

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

Affected products

  • Grafana Grafana: from 12.0, before 12.0.2+security-01 (fixed in 12.0.2+security-01); from 11.6, before 11.6.3+security-01 (fixed in 11.6.3+security-01); from 11.5, before 11.5.6+security-01 (fixed in 11.5.6+security-01); from 11.4, before 11.4.6+security-01 (fixed in 11.4.6+security-01); from 11.3, before 11.3.8+security-01 (fixed in 11.3.8+security-01)

Published 2025-07-18. Last modified 2026-06-17.