[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Token Exfiltration

articleHIGH 8.6

Critical Confused-Deputy Flaw in Grafana MCP Server Enables Token Exfiltration and SSRF

A high-severity vulnerability (CVE-2026-15583, CVSS 8.6) in Grafana MCP Server allows unauthenticated remote attackers to exfiltrate environment-configured Grafana service-account tokens and conduct SSRF attacks against internal services. The flaw has not been actively exploited but poses a significant risk due to its potential impact. Organizations using Grafana MCP Server version 0.17.1 or earlier are advised to upgrade immediately.

Jul 16, 20261 source