CVE-2026-15583: Grafana Mcp Server
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
Affected products
- Grafana Grafana Mcp Server: from 0.0.0, up to and including 0.17.1
Published 2026-07-15. Last modified 2026-07-15.