DIRAS TAKE
Urgent: public exploit code exists for this SSRF, so prioritize mitigation for internet-facing or broadly reachable MCP instances and restrict outbound requests from the service immediately.
What is CVE-2026-19516?
An attacker who can send requests to Grafana MCP Server can make the product issue arbitrary outbound HTTP requests and read the responses, potentially reaching internal, loopback, link-local, and metadata endpoints. This is tracked as CVE-2026-19516. The flaw affects Grafana MCP Server 1.x (1.0.0 and earlier) and mcp-grafana 1.x (1.0.0 and earlier). An attacker only needs network access to the MCP service and the ability to supply the X-Grafana-URL header and request data to trigger the behavior. The weakness is classified as CWE-918 (Server-Side Request Forgery).
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Which versions of Grafana Grafana MCP Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Grafana MCP Server 1.x | 1.0.0 and earlier | |
| mcp-grafana 1.x | 1.0.0 and earlier |
Is CVE-2026-19516 being exploited?
Public exploit code is available.
How to fix CVE-2026-19516
- Block or filter incoming requests that set or control the X-Grafana-URL header at network or application gateways.
- Restrict outbound HTTP access from Grafana MCP Server to only the configured Grafana instance and trusted destinations using egress firewall rules.
- Apply the vendor's guidance and monitor application and network logs for unusual MCP-originated requests to internal, loopback, or metadata endpoints.
- Rotate any credentials or tokens that might have been accessible to services reachable from the MCP host and review for signs of misuse.
Frequently asked questions
Is CVE-2026-19516 being actively exploited?
Public exploit code is available for CVE-2026-19516, indicating a higher risk of active exploitation.
Which Grafana MCP Server versions are affected by CVE-2026-19516?
Grafana MCP Server 1.x (1.0.0 and earlier) and mcp-grafana 1.x (1.0.0 and earlier) are listed as affected.
Is there a patch for CVE-2026-19516?
No fixed versions are listed for CVE-2026-19516 in the provided facts; follow vendor guidance and apply mitigations to restrict exposure.
What can an attacker do with CVE-2026-19516?
An attacker can cause Grafana MCP Server to send arbitrary HTTP requests and read responses, potentially accessing internal, loopback, link-local services and metadata endpoints.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19516
- cve.org/CVERecord?id=CVE-2026-19516
- grafana.com/security/security-advisories/cve-2026-19516
- All Grafana CVEs on CVE Radar
- CVEs published in September 2026