VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-15583

CVE-2026-15583: A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro

Published Jul 15, 2026 CVSS 8.6

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.