Tag
#Grafana
Critical Confused-Deputy Flaw in Grafana MCP Server Enables Token Exfiltration and SSRF
A high-severity vulnerability (CVE-2026-15583, CVSS 8.6) in Grafana MCP Server allows unauthenticated remote attackers to exfiltrate environment-configured Grafana service-account tokens and conduct SSRF attacks against internal services. The flaw has not been actively exploited but poses a significant risk due to its potential impact. Organizations using Grafana MCP Server version 0.17.1 or earlier are advised to upgrade immediately.
CVE-2026-42129: Grafana Loki Datasource Plugin Path Traversal Vulnerability
A path traversal vulnerability in the Grafana Loki datasource plugin allows an authenticated Viewer-role user to access administrative Loki endpoints and extract sensitive backend configuration and internal service information. This vulnerability has a CVSS score of 7.7 and is considered HIGH severity. Affected users should update Grafana OSS to a patched version.