A newly disclosed server-side request forgery flaw, CVE-2026-19516, affects Grafana MCP Server and mcp-grafana in versions prior to or equal to 1.0.0. The vulnerability allows a caller-controlled X-Grafana-URL header to steer outbound requests to attacker-chosen destinations, while the grafana_api_request tool lets the caller select the HTTP method, path, and body. That combination can be abused to reach internal, loopback, and link-local services, including cloud metadata endpoints, and read back the responses.
The issue remains exploitable despite an earlier fix for CVE-2026-15583, which prevented the configured Grafana service-account token from being sent to unintended destinations but did not restrict where requests could be sent. The Canadian Centre for Cyber Security issued advisory AV26-796, warning that Grafana products are affected and urging administrators to review vendor guidance and apply updates when available.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On August 11, 2026, the Canadian Centre for Cyber Security issued advisory AV26-796 for CVE-2026-19516. The notice said Grafana MCP Server and mcp-grafana versions prior to or equal to 1.0.0 are affected and advised users to review vendor guidance and apply updates when available.
Security updates were released to remediate two high-severity vulnerabilities affecting Grafana products. According to the reference, successful exploitation could expose sensitive information, bypass security restrictions, and affect service availability.
CVE-2026-19516 was disclosed as a server-side request forgery vulnerability affecting mcp-grafana. The issue stems from a caller-controlled X-Grafana-URL header and a tool that lets the caller choose the HTTP method, path, and body, enabling requests to unintended internal destinations and reading their responses.
A prior fix for CVE-2026-15583 prevented mcp-grafana from sending the configured Grafana service-account token to unintended destinations, but it did not restrict where outbound requests could be sent. This left SSRF-style access to internal, loopback, link-local, and metadata endpoints possible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecve.org
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.