CVE-2026-15583: Grafana Mcp Server

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.

Affected products

  • Grafana Grafana Mcp Server: from 0.0.0, up to and including 0.17.1

Published 2026-07-15. Last modified 2026-07-15.