Grafana patched CVE-2026-19516, a critical SSRF vulnerability with a CVSS score of 9.1 in the Grafana MCP server's grafana_api_request tool. The flaw allowed callers to control outbound HTTP requests through a supplied X-Grafana-URL header, potentially reaching internal services accessible from the MCP server and reading their responses. In tested deployments, the issue could expose sensitive data such as AWS IMDSv2 credentials.
Researchers also found that attacker-generated values matching the expected session-ID format could bypass session validation and invoke MCP tools, including tools/list and tools/call, without authentication under the configured Grafana service account. Grafana addressed both issues in version 1.1.0 by fixing the SSRF condition and adding optional bearer-token authentication; operators should enforce authentication on remote MCP deployments, restrict service-account privileges, and apply strict outbound destination filtering.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Grafana MCP version 1.1.0 fixed CVE-2026-19516 and introduced optional bearer-token authentication to prevent unauthenticated tool execution when configured.
Pillar Security reported CVE-2026-19516, a CVSS 9.1 SSRF flaw in the grafana_api_request tool. Caller-controlled X-Grafana-URL values could cause the MCP server to issue requests to internal destinations and return their responses; testing demonstrated possible AWS IMDSv2 credential retrieval in certain deployments.
Pillar Security found that Grafana MCP accepted locally generated session-shaped IDs based on format rather than validating issued credentials, allowing unauthenticated callers to invoke MCP tools using the configured Grafana service account.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.