Server-Side Request Forgery in mcp-grafana Affects Grafana by Grafana Labs
CVE-2026-19516
9.1CRITICAL
What is CVE-2026-19516?
mcp-grafana allows an attacker to manipulate the X-Grafana-URL request header, which can direct outbound requests to unintended internal destinations, including sensitive network services and metadata endpoints. This oversight permits attackers to exploit the system for unauthorized data access, making it crucial to implement strict controls over outbound request destinations to mitigate the risks associated with this vulnerability.
Affected Version(s)
Grafana MCP Server 0.0.0 <= 1.0.0
mcp-grafana 0.0.0 <= 1.0.0