Cross-Tenant Credential Reuse in HashiCorp Terraform MCP Server
CVE-2026-16498

10CRITICAL

Key Information:

Vendor

Hashicorp

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-16498?

A cross-tenant credential reuse vulnerability exists in the Terraform MCP Server before version 1.1.0. This issue may allow a user's Terraform token to be misappropriated, enabling unauthorized execution of tool calls on behalf of subsequent users in the streamable-HTTP stateless transport mode. Proper updates and patches are essential to mitigate the risks associated with this vulnerability, as it compromises user security and data integrity.

Affected Version(s)

Tooling 64 bit 0.3.0 < 1.1.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was identified by an internal team.
.