PT-2026-65551 · Unknown · Terraform-Mcp-Server

CVE-2026-16498

·

Published

2026-07-28

·

Updated

2026-08-17

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions terraform-mcp-server versions prior to 1.1.0
Description A cross-tenant credential reuse issue exists in the streamable-HTTP stateless transport mode. This flaw may allow a Terraform token belonging to one user to be reused to execute tool calls on behalf of subsequent users.
Recommendations Update to version 1.1.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CONSUL-2026-16498
CVE-2026-16498

Affected Products

Terraform-Mcp-Server