Impact
A confused‑deputy flaw in Grafana MCP Server permits an unauthenticated attacker to cause the server to treat a crafted X‑Grafana‑URL header as a trusted request. The server dutifully performs the requested action, allowing the attacker to retrieve the server’s environment‑configured Grafana service‑account token and use the same mechanism to reach arbitrary internal services, including cloud metadata endpoints. This vulnerability exposes privileged credentials and permits the attacker to probe or exfiltrate data from the internal network, potentially escalating to further compromise.
Affected Systems
The flaw impacts Grafana MCP Server deployments. No specific product version is listed, so any installation that processes X‑Grafana‑URL requests is potentially vulnerable until the vendor issues a fix.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity threat. EPSS data shows a low probability (< 1%) of exploitation, and the vulnerability is not listed in CISA's KEV catalog, but the attack can be performed simply by sending an HTTP request with a crafted header from any network that can reach the Grafana MCP Server. The only prerequisites are network connectivity and no authentication, making it a likely vector for attackers scanning for exposed Grafana services.
OpenCVE Enrichment