Cross-Tenant Credential Reuse in HashiCorp Terraform MCP Server
CVE-2026-16498
10CRITICAL
What is CVE-2026-16498?
A cross-tenant credential reuse vulnerability exists in the Terraform MCP Server before version 1.1.0. This issue may allow a user's Terraform token to be misappropriated, enabling unauthorized execution of tool calls on behalf of subsequent users in the streamable-HTTP stateless transport mode. Proper updates and patches are essential to mitigate the risks associated with this vulnerability, as it compromises user security and data integrity.
Affected Version(s)
Tooling 64 bit 0.3.0 < 1.1.0