CVE-2026-15583

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
Configurations

No configuration.

History

15 Jul 2026, 15:16

Type Values Removed Values Added
CWE CWE-610

15 Jul 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 08:16

Updated : 2026-07-15 20:56


NVD link : CVE-2026-15583

Mitre link : CVE-2026-15583

CVE.ORG link : CVE-2026-15583


JSON object : View

Products Affected

No product.

CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere