CVE-2026-15583Disclosed before NVD

Grafana MCP server-side request forgery via X-Grafana-URL header

Published
July 15, 2026
Last Modified

📋 Description

A vulnerability has been discovered in the mcp-grafana project (https://github.com/grafana/mcp-grafana) where a confused-deputy flaw allows an unauthenticated remote attacker to exfiltrate the server’s environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This vulnerability is classified as Server-Side Request Forgery (SSRF) and also enables credentialed SSRF against arbitrary internal services, including cloud metadata endpoints. Upgrade to a fixed version listed below.

🎯 Affected products1

  • Grafana

🔗 References (1)