CyberRota Analysis
AI-GeneratedThe terraform-mcp-server prior to version 1.1.0 is susceptible to an authorization bypass that enables an attacker with access to another user's MCP session ID to execute commands using that user's Terraform credentials. This poses a significant risk as it could lead to unauthorized access and manipulation of infrastructure resources. Organizations utilizing terraform-mcp-server should prioritize upgrading to version 1.1.0 or later to mitigate this vulnerability.
Original NVD Description
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.