SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-15583

HIGH · CVSS 8.6 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Grafana MCP Server is vulnerable to a confused-deputy flaw that allows unauthenticated remote attackers to exfiltrate the service-account token by manipulating the X-Grafana-URL request header. This vulnerability also facilitates server-side request forgery (SSRF) attacks against internal services, potentially exposing sensitive cloud metadata. Organizations using Grafana MCP Server should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data leakage.

CVE
CVE-2026-15583
Severity
HIGH
CVSS
8.6
EPSS
0.49%

Original NVD Description

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.