Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-16498: Terraform MCP Server Credentials Can Be Shared Across Users

CVE-2026-16498 · published 18 days ago
Summary

The Terraform MCP Server before version 1.1.0 allows one user's credentials to be used by other users. This means that if one user's credentials are compromised, an attacker could use them to access and execute actions on behalf of other users. To fix this, update to version 1.1.0 or later.

What to do
  • Update consul to version 1.1.0.
  • Update hashicorp tooling to version 1.1.0 or later.
Affected software
Ecosystem VendorProductAffected versions
hashicorp tooling < 1.1.0
Bitnami consul >= 0.3.0, < 1.1.0
Fix: upgrade to 1.1.0
Original advisory text
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-488Exposure of Data Element to Wrong Session
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen28 Jul 2026
Sources
CVE-2026-16498 · MITRE
Monitor software like this
Free during beta