A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
References
Configurations
No configuration.
History
15 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-610 |
15 Jul 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 08:16
Updated : 2026-07-15 20:56
NVD link : CVE-2026-15583
Mitre link : CVE-2026-15583
CVE.ORG link : CVE-2026-15583
JSON object : View
Products Affected
No product.
CWE
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
