Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4305 articles · 196685 vulns · 37/41 feeds (7d)
← Back to list
8.6
CVE-2026-14869PATCHED
hashi · tooling

terraform-mcp-server vulnerable to server side request forgery leading to token exposure

Description

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.

Affected Products

VendorProductVersions
hashitooling0.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
hashiterraformcert_advisory90%

References

  • https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606

Related News (4 articles)

Tier D
The Hacker News14d ago
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
→ No new info (linked only)
Tier D
The Hacker News19d ago
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
→ No new info (linked only)
Tier B
BSI Advisories26d ago
[NEU] [hoch] Hashicorp Terraform MCP Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB27d ago
CVE-2026-14869 | HashiCorp terraform-mcp-server up to 1.0.x Streamable-HTTP Transport server-side request forgery
→ No new info (linked only)
CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.1.0
CWECWE-918
PublishedJul 28, 2026
Trending Score11
Source articles4
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-14978
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
Trending: 33
CRITICALCVE-2026-16498
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 13
HIGHCVE-2026-19589
Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Trending: 10
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 10
HIGHCVE-2026-14886
Vault Enterprise vulnerable to cross-namespace entity deletion
Trending: 9

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 28, 2026