CyberRota
← Ana sayfaya dön

CVE-2026-14869

HIGH · CVSS 8.6

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-28T19:17:31.423 · Çekilme zamanı: 2026-07-29T00:07:42.260685+00:00

CyberRota Yorumu

Uzaktan istismar edilebilir olabilir.

CVE
CVE-2026-14869
Severity
HIGH
CVSS
8.6
EPSS
Yok

Orijinal NVD Açıklaması

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.