Server-Side Request Forgery in mcp-grafana Affects Grafana by Grafana Labs
CVE-2026-19516

9.1CRITICAL

Key Information:

Vendor

Grafana

Vendor
CVE Published:
11 August 2026

What is CVE-2026-19516?

mcp-grafana allows an attacker to manipulate the X-Grafana-URL request header, which can direct outbound requests to unintended internal destinations, including sensitive network services and metadata endpoints. This oversight permits attackers to exploit the system for unauthorized data access, making it crucial to implement strict controls over outbound request destinations to mitigate the risks associated with this vulnerability.

Affected Version(s)

Grafana MCP Server 0.0.0 <= 1.0.0

mcp-grafana 0.0.0 <= 1.0.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

foguel (Researcher)
.