Authorization Bypass in HashiCorp Terraform MCP Server
CVE-2026-16496

8.9HIGH

Key Information:

Vendor

Hashicorp

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-16496?

The Terraform MCP Server prior to version 1.1.0 is susceptible to an authorization bypass vulnerability in its streamable-HTTP stateful transport mode. This flaw allows an unauthorized user to exploit another user's MCP session ID, enabling them to execute tool calls using the victim's Terraform credentials. This poses a significant security risk, potentially allowing for unauthorized access to sensitive data and operations within the user's Terraform environment.

Affected Version(s)

Tooling 64 bit 0.3.0 < 1.1.0

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Juan Pablo Martinez Kuhn of Coinspect.
.