securityonline.info 8/4/2026, 3:12:01 PM · external

Terraform MCP Server Flaw CVE-2026-16498 Scores CVSS 10.0

Terraform MCP Server Flaw CVE-2026-16498 Scores CVSS 10.0
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

HASHICORP has addressed three critical vulnerabilities in its Terraform MCP Server, with the most severe flaw (CVE-2026-16498) receiving a maximum CVSS score of 10.0. These vulnerabilities can expose Terraform tokens in multi-user setups, potentially allowing attacks on cloud infrastructure. The affected versions range from 0.2.1 to 1.0.0, and users are advised to upgrade to version 1.1.0 immediately. There is currently no confirmed exploitation of these vulnerabilities.

Further details reveal that one flaw allows session token reuse across tenants due to poor session isolation, while others involve stealing session IDs or redirecting tokens.

View Primary Source Via securityonline.info

Article by CyberSIXT