The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.

Project Subscriptions

Vendors Products
Hashicorp Subscribe
Tooling Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp tooling
Vendors & Products Hashicorp
Hashicorp tooling

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.
Title terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 8.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-07-28T18:43:58.385Z

Reserved: 2026-07-21T16:53:07.388Z

Link: CVE-2026-16496

cve-icon Vulnrichment

Updated: 2026-07-28T18:42:50.919Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T19:30:16Z

Weaknesses