CyberRota
← Ana sayfaya dön

CVE-2026-16496

HIGH · CVSS 8.9

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-28T19:17:31.983 · Çekilme zamanı: 2026-07-29T00:07:42.363795+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-16496
Severity
HIGH
CVSS
8.9
EPSS
Yok

Orijinal NVD Açıklaması

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.