Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-15583 — Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks service-account tokens via X-Grafana-URL. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-15583
Vulnerability AnalysisExploitationServerless SecurityWeb Application ExploitationData ExfiltrationSecurity VirtualizationPenetration TestingAPI SecurityLabs & Practice
GitHubabraxas/cve-2026-15583

CVE-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks service-account tokens via X-Grafana-URL.

112 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs - CVE-2026-15583

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-15583

CVE-2026-15583

Grafana MCP Server 0.17.0 - Grafana Labs

I am @abraxas_null. Loopback lab. The client is CVE-2026-15583-Abraxas-Labs.py.

Confused deputy. Unauthenticated MCP HTTP takes X-Grafana-URL from the request and the service-account token from the environment, then GET {url}/api/frontend/settings with Authorization: Bearer. Empty X-Grafana-Service-Account-Token falls back to env. Fixed in 0.17.1 by not sending the configured token to unintended destinations.

CVECVE-2026-15583 · CVE.org
CWECWE-918
CVSSHigh: 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
ProductGrafana MCP Server
Affectedall versions through 0.17.0 (inclusive)
Patched0.17.1 and later
Authunauthenticated
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

POST /mcp or GET /sse with X-Grafana-URL pointing at a collector you control. The server ships GRAFANA_SERVICE_ACCOUNT_TOKEN (or GRAFANA_API_KEY) to you. That is credentialed SSRF plus token theft. Lab oracle is the witness token in the collector Authorization header.


How I found it

I mapped extractKeyGrafanaInfoFromReq / ExtractGrafanaInfoFromHeaders, then NewGrafanaClient fetchPublicURL, then AuthRoundTripper. Stood up mcp-grafana 0.17.0 with a loopback collector.

Fail-controls already in the lab: eval/base64/system is not the witness; a reverse shell is not the witness; 0.17.1 must not send the env token to the collector.


The lab

Port 18099. mcp-grafana 0.17.0. SSE or streamable-http reachable. Env token set. Collector on the compose network.

  • lab/Dockerfile
  • lab/docker-compose.yml
  • lab/run.sh

Target only 127.0.0.1:18099 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-15583-Abraxas-Labs.py

Witness: Collector Authorization header contains GHSA15583-WITNESS.

Ways to lose without learning anything:

  • eval / base64 / system payload
  • reverse shell
  • patched 0.17.1

The fix

Update Grafana MCP Server to 0.17.1 or newer. Re-run CVE-2026-15583-Abraxas-Labs.py against the patched build: the collector must not see the env token.


References

  • CVE-2026-15583 · NVD

  • CVE-2026-15583 · CVE.org

  • grafana.com/security/security-advisories/cve-2026-15583/

  • github.com/grafana/mcp-grafana

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool