• PoC PUBLIC

CVE-2026-19516: server-side request forgery in Grafana Grafana MCP Server

An attacker who can send requests to Grafana MCP Server can make the product issue arbitrary outbound HTTP requests and read the responses, potentially reaching internal, loopback, link-local, and metadata endpoints. This is tracked as CVE-2026-19516. The flaw affects Grafana MCP Server 1.x (1.0.0 and earlier) and mcp-grafana 1.x (1.0.0 and earlier). An attacker only needs network access to the MCP service and the ability to supply the X-Grafana-URL header and request data to trigger the behavior.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.1CRITICAL
EPSS
0.0031
CWE
CWE-918
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists for this SSRF, so prioritize mitigation for internet-facing or broadly reachable MCP instances and restrict outbound requests from the service immediately.

What is CVE-2026-19516?

An attacker who can send requests to Grafana MCP Server can make the product issue arbitrary outbound HTTP requests and read the responses, potentially reaching internal, loopback, link-local, and metadata endpoints. This is tracked as CVE-2026-19516. The flaw affects Grafana MCP Server 1.x (1.0.0 and earlier) and mcp-grafana 1.x (1.0.0 and earlier). An attacker only needs network access to the MCP service and the ability to supply the X-Grafana-URL header and request data to trigger the behavior. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Which versions of Grafana Grafana MCP Server are affected?

BRANCHAFFECTEDFIXED
Grafana MCP Server 1.x1.0.0 and earlier
mcp-grafana 1.x1.0.0 and earlier

Is CVE-2026-19516 being exploited?

Public exploit code is available.

How to fix CVE-2026-19516

  1. Block or filter incoming requests that set or control the X-Grafana-URL header at network or application gateways.
  2. Restrict outbound HTTP access from Grafana MCP Server to only the configured Grafana instance and trusted destinations using egress firewall rules.
  3. Apply the vendor's guidance and monitor application and network logs for unusual MCP-originated requests to internal, loopback, or metadata endpoints.
  4. Rotate any credentials or tokens that might have been accessible to services reachable from the MCP host and review for signs of misuse.

Frequently asked questions

Is CVE-2026-19516 being actively exploited?

Public exploit code is available for CVE-2026-19516, indicating a higher risk of active exploitation.

Which Grafana MCP Server versions are affected by CVE-2026-19516?

Grafana MCP Server 1.x (1.0.0 and earlier) and mcp-grafana 1.x (1.0.0 and earlier) are listed as affected.

Is there a patch for CVE-2026-19516?

No fixed versions are listed for CVE-2026-19516 in the provided facts; follow vendor guidance and apply mitigations to restrict exposure.

What can an attacker do with CVE-2026-19516?

An attacker can cause Grafana MCP Server to send arbitrary HTTP requests and read responses, potentially accessing internal, loopback, link-local services and metadata endpoints.

References