terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.9epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Affected products
HashiCorp · Tooling