VENDOR

Grafana vulnerabilities: CVEs, exploitation and patches

Every Grafana CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-19516
    Grafana MCP Server server-side request forgery (SSRF) Grafana Grafana MCP Server ·
    • PoC PUBLIC
    CRITICAL 9.1
  2. CVE-2026-15583
    Grafana MCP Server confused-deputy header token exfiltration and SSRF Grafana Grafana MCP Server ·
    • PoC PUBLIC
    HIGH 8.6
2 CVEs · page 1 of 1