


Perceptive Security
SOC/SIEM Consultancy

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may al…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 20:07:40
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access, Enterprise Applications
CVE-2026-16498 affects terraform-mcp-server versions prior to 1.1.0, exposing a cross-tenant credential reuse vulnerability in the streamable-HTTP stateless transport mode. The flaw allows one user's Terraform token to be leveraged to execute tool calls on behalf of subsequent users, creating a significant identity and access control risk. This is particularly dangerous in multi-tenant environments where credential isolation is critical. The vulnerability has been patched in terraform-mcp-server version 1.1.0. HashiCorp disclosed the issue via their security advisory HCSEC-2026-23, which also references multiple vulnerabilities impacting the same server. Users are strongly advised to upgrade to version 1.1.0 or later to remediate the issue.
Technical details
Mitigation steps:
Affected products:
terraform-mcp-server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-16498
https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
