Vendor
Grafana Improper Access Control Information Disclosure Vulnerability
2 TTPs 1 CVEAn authenticated, remote attacker can exploit a flaw in Grafana to perform unauthorized information disclosure due to improper access control.
Security Advisory for Grafana MCP Server and mcp-grafana
1 CVEGrafana Labs has addressed a security vulnerability identified as CVE-2026-19516 affecting the Grafana MCP Server and mcp-grafana components in versions 1.0.0 and earlier.
Grafana MCP Server SSRF and Loki DoS Vulnerabilities Addressed
1 rule 3 TTPs 2 CVEsGrafana has published security advisories for vulnerabilities in Grafana MCP Server (CVE-2026-15583), leading to server-side request forgery, and Grafana Loki (CVE-2026-21729), resulting in unbounded memory allocation and denial of service, impacting versions 0.17.1 and prior for MCP Server and 3.7.0 and prior for Loki, urging users to update to mitigate potential exploitation.
Grafana OnCall Unauthenticated Access Vulnerability (CVE-2026-63087)
4 TTPs 1 CVEA critical unauthenticated access vulnerability, CVE-2026-63087, in Grafana OnCall through version 1.16.11 allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to an internal plugin install endpoint using hardcoded default stack_id and org_id values, enabling authentication to all internal API endpoints, creation of arbitrary administrative users, and redirection of API calls to an attacker-controlled host.
Multiple Vulnerabilities in Grafana Could Lead to DoS and XSS
2 TTPsAttackers can exploit multiple vulnerabilities in Grafana to conduct Denial of Service attacks or Cross-Site Scripting attacks, potentially leading to service disruption or client-side code execution.