Cross-Tenant Credential Reuse in HashiCorp Terraform MCP Server
CVE-2026-16498

10CRITICAL

Key Information:

Vendor

Hashicorp

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-16498?

CVE-2026-16498 is a vulnerability found in the HashiCorp Terraform MCP Server prior to version 1.1.0. HashiCorp Terraform is an open-source infrastructure as code software tool that allows users to define and provision data center infrastructure using a high-level configuration language. The vulnerability involves a cross-tenant credential reuse issue, specifically within the server's streamable-HTTP stateless transport mode. This flaw may permit a user's Terraform token to be misused, allowing one user to execute commands on behalf of another user, leading to unauthorized actions and potential data exposure.

If exploited, this vulnerability could enable malicious users to gain access to resources and sensitive information within other users' sessions, ultimately jeopardizing the integrity and confidentiality of the affected environment. Organizations relying on Terraform MCP for infrastructure management could face significant operational disruptions and security risks if this vulnerability is not addressed promptly.

Potential impact of CVE-2026-16498

  1. Unauthorized Access: The vulnerability allows one user's credentials to be exploited in another user's session, potentially enabling unauthorized access to critical infrastructure and sensitive data. This could lead to data breaches or data manipulation, severely impacting operational integrity.

  2. Data Compromise: With the ability to execute commands on behalf of another user, attackers could access, modify, or delete sensitive information. This unauthorized access could result in significant financial and reputational damage to the affected organization.

  3. Operational Disruptions: Exploitation of this vulnerability could lead to misconfigurations or unwanted changes to infrastructure components, potentially causing downtime or degradation of service for users. Consequently, this can disrupt business operations and lead to additional recovery costs.

Affected Version(s)

Tooling 64 bit 0.3.0 < 1.1.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was identified by an internal team.
.