Grafana · Grafana Mcp Server · CVE-2026-15583
**Name of the Vulnerable Software and Affected Versions**
Grafana MCP Server (affected versions not specified)
**Description**
A confused-deputy flaw allows an unauthenticated remote attacker to exfiltrate the environment-configured Grafana service-account token. This is achieved by supplying a crafted `X-Grafana-URL` request header. Additionally, this issue enables Server-Side Request Forgery (SSRF), which allows the attacker to make requests to arbitrary internal services, including cloud metadata endpoints. SSRF is a technique where an attacker induces a server-side application to make requests to an unintended location.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.