Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2981 articles · 185100 vulns · 37/41 feeds (7d)
← Back to list
8.6
CVE-2026-14869PATCHED
hashi · tooling

terraform-mcp-server vulnerable to server side request forgery leading to token exposure

Description

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.

Affected Products

VendorProductVersions
hashitooling0.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
hashiterraformcert_advisory90%

References

  • https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606

Related News (3 articles)

Tier D
The Hacker News3d ago
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
→ No new info (linked only)
Tier B
BSI Advisories10d ago
[NEU] [hoch] Hashicorp Terraform MCP Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-14869 | HashiCorp terraform-mcp-server up to 1.0.x Streamable-HTTP Transport server-side request forgery
→ No new info (linked only)
CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.1.0
CWECWE-918
PublishedJul 28, 2026
Trending Score34
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16498
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 40
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 31
CRITICALCVE-2026-16326
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 12
HIGHCVE-2026-16328
consul-mcp-server vulnerable to server side request forgery leading to token exposure
Trending: 11
HIGHCVE-2026-14468
Path traversal allows arbitrary file read in Terraform Enterprise container
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 28, 2026