๐Ÿ” CVE Alert

CVE-2026-19516

CRITICAL 9.1

CVE-2026-19516 CVE Record

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and read the responses, resulting in server-side request forgery. The fix for CVE-2026-15583 prevented the configured service-account token from being sent to unintended destinations but did not restrict the destinations themselves.

CWE CWE-918
Vendor grafana
Product grafana mcp server
Ecosystems
Industries
Technology
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for grafana grafana mcp server

Be the first to know when new critical vulnerabilities affecting grafana grafana mcp server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Grafana / Grafana MCP Server
0.0.0 โ‰ค 1.0.0
Grafana / mcp-grafana
0.0.0 โ‰ค 1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
grafana.com: https://grafana.com/security/security-advisories/cve-2026-19516

Credits

foguel (Researcher)