SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16498

CRITICAL · CVSS 10 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The terraform-mcp-server prior to version 1.1.0 is susceptible to a critical cross-tenant credential reuse vulnerability that enables an attacker to exploit one user's Terraform token to perform unauthorized actions on behalf of other users. This flaw poses a significant risk to organizations using this tool, as it could lead to unauthorized access and manipulation of resources. All users of terraform-mcp-server should prioritize upgrading to version 1.1.0 or later to mitigate this severe security risk.

CVE
CVE-2026-16498
Severity
CRITICAL
CVSS
10
EPSS
0.46%

Original NVD Description

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.