Server-Side Request Forgery in mcp-grafana Affects Grafana by Grafana Labs
CVE-2026-19516

9.1CRITICAL

Key Information:

Vendor

Grafana

Vendor
CVE Published:
11 August 2026

Badges

πŸ“ˆ TrendedπŸ“ˆ Score: 3,280πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-19516?

CVE-2026-19516 is a security vulnerability affecting mcp-grafana, a component of the Grafana data visualization platform developed by Grafana Labs. Grafana is widely utilized for monitoring and visualizing time series data across various applications and infrastructures. This particular vulnerability arises from a server-side request forgery (SSRF) flaw, which allows unauthorized users to manipulate outbound requests made by mcp-grafana. A user can leverage a crafted request header to redirect these outbound requests to unintended destinations, including internal and private network services. This can lead to unauthorized access to sensitive data and systems within an organization, potentially exposing internal APIs or services that are not meant to be accessed externally.

Potential impact of CVE-2026-19516

  1. Unauthorized Data Access: Attackers could exploit this vulnerability to gain access to internal network services that are typically secured and not accessible from the outside. This could result in unauthorized exposure of sensitive data or application interfaces.

  2. Internal Network Scanning: By manipulating outbound requests, an attacker can probe internal systems, potentially revealing valuable information about the organization's network architecture and available services. This reconnaissance can be leveraged for further exploits.

  3. Compromise of Internal Services: If an attacker can access and interact with internal APIs or services, they may be able to perform malicious actions, such as data exfiltration or further injection of malicious payloads, increasing the potential for broader system compromise and operational disruptions.

Affected Version(s)

Grafana MCP Server 0.0.0 <= 1.0.0

mcp-grafana 0.0.0 <= 1.0.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

foguel (Researcher)
.