Junglewise Threat Intelligence

CVE-2026-15583: Grafana MCP Server SSRF and token exfiltration via X-Grafana-URL

CVE-2026-15583 · Severity: high · CVSS 8.6 · Published 2026-07-15

Vendors: Grafana Labs.

Executive brief

A security vulnerability in the Grafana MCP Server allows unauthorized individuals to steal sensitive service-account tokens. By sending a specially crafted web request, an attacker can trick the server into revealing its credentials or accessing private internal systems, such as cloud management interfaces. This could lead to unauthorized access to your monitoring infrastructure and broader cloud environment.

Technical details

A confused-deputy vulnerability exists in the Grafana MCP Server due to improper handling of the 'X-Grafana-URL' request header. An unauthenticated remote attacker can exploit this by providing a malicious URL in the header, causing the server to forward its own environment-configured service-account token to an attacker-controlled endpoint. Additionally, this flaw facilitates Server-Side Request Forgery (SSRF), allowing attackers to probe or interact with internal network services and cloud metadata services (e.g., IMDS). The vulnerability affects versions up to and including 0.17.1.

Affected products

  • Grafana Labs Grafana MCP Server <= 0.17.1

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory

References