Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4305 articles · 196685 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-16498PATCHED
hashi · tooling

terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

Description

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.

Affected Products

VendorProductVersions
hashitooling0.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
hashiterraformcert_advisory90%

References

  • https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606

Related News (4 articles)

Tier D
The Hacker News14d ago
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
→ No new info (linked only)
Tier D
The Hacker News19d ago
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
→ No new info (linked only)
Tier B
BSI Advisories26d ago
[NEU] [hoch] Hashicorp Terraform MCP Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB27d ago
CVE-2026-16498 | HashiCorp terraform-mcp-server up to 1.0.9 Streamable-HTTP Stateless Transport Mode state issue
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.1.0
CWECWE-488
PublishedJul 28, 2026
Trending Score13
Source articles4
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-14978
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
Trending: 33
HIGHCVE-2026-14869
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
Trending: 11
HIGHCVE-2026-19589
Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Trending: 10
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 10
HIGHCVE-2026-14886
Vault Enterprise vulnerable to cross-namespace entity deletion
Trending: 9

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 28, 2026