What is CVE-2026-19516?
The vulnerability CVE-2026-19516 in mcp-grafana allows an attacker to manipulate the X-Grafana-URL header, redirecting outbound requests to arbitrary destinations and potentially performing SSRF attacks. Users should update mcp-grafana to the latest version and enforce strict access controls.
Azərbaycanca: CVE-2026-19516 boşluğu mcp-grafana alətində aşkar edilmişdir. Burada təcavüzkar X-Grafana-URL başlığı vasitəsilə sorğuları konfiqurasiya edilmiş Grafana instansiyasından kənara istiqamətləndirərək SSRF hücumu həyata keçirə bilər. İstifadəçilər mcp-grafana-nı ən son versiyaya yeniləməli və giriş nəzarətlərini sərtləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ1
What can an attacker do by exploiting CVE-2026-19516?
An attacker can manipulate the X-Grafana-URL header to redirect outbound requests beyond the configured Grafana instance and perform an SSRF attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.