CVE-2026-15583
HIGHSSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-15583. PoCs published by codeb0ssx.
AI-analyzed exploit summary The repository contains obfuscated Python code using PyArmor, a commercial code protection tool. The main script (`CVE-2026-15583.py`) loads an encrypted payload with no clear exploit logic, while the `pytransform` module is a known PyArmor component used to decrypt and execute obfuscated code. The presence of binary blobs and lack of technical details about the vulnerability suggest malicious intent.
Description
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
Exploits (1)
The repository contains obfuscated Python code using PyArmor, a commercial code protection tool. The main script (`CVE-2026-15583.py`) loads an encrypted payload with no clear exploit logic, while the `pytransform` module is a known PyArmor component used to decrypt and execute obfuscated code. The presence of binary blobs and lack of technical details about the vulnerability suggest malicious intent.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N