DIRAS TAKE
Urgent: public exploit code exists and the bug is exploitable without authentication, so prioritize reducing exposure of internet-facing Grafana MCP Server instances and apply vendor guidance immediately.
What is CVE-2026-15583?
An unauthenticated remote attacker can use a crafted X-Grafana-URL request header to make Grafana MCP Server expose its environment-configured Grafana service-account token and to perform SSRF to internal services, including cloud metadata endpoints. CVE-2026-15583 affects Grafana MCP Server 0.x, specifically 0.17.1 and earlier. The flaw requires network access to the Grafana MCP Server endpoint but does not require valid credentials or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Which versions of Grafana Grafana MCP Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 0.x | 0.17.1 and earlier |
Is CVE-2026-15583 being exploited?
Public exploit code is available.
How to fix CVE-2026-15583
- Restrict network exposure: block or firewall access to Grafana MCP Server from untrusted networks.
- Apply vendor guidance and follow any hardening steps Grafana publishes for MCP Server.
- Limit outbound access from the server and restrict egress to internal metadata and sensitive services.
- Rotate any service-account tokens that may have been exposed and monitor for use of those tokens.
Frequently asked questions
Is CVE-2026-15583 being actively exploited?
Public exploit code for CVE-2026-15583 is available.
Which Grafana MCP Server versions are affected by CVE-2026-15583?
Grafana MCP Server 0.x is affected; the vendor notes 0.17.1 and earlier are vulnerable.
Is there a patch for CVE-2026-15583?
There is no fixed version listed for CVE-2026-15583 in the provided facts; follow Grafana's guidance and apply mitigations.
Does CVE-2026-15583 require authentication?
No; CVE-2026-15583 can be exploited by an unauthenticated remote attacker with network access to the Grafana MCP Server.
References
- nvd.nist.gov/vuln/detail/CVE-2026-15583
- cve.org/CVERecord?id=CVE-2026-15583
- grafana.com/security/security-advisories/cve-2026-15583
- All Grafana CVEs on CVE Radar
- CVEs published in September 2026