SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16496

HIGH · CVSS 8.9 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The terraform-mcp-server prior to version 1.1.0 is susceptible to an authorization bypass that enables an attacker with access to another user's MCP session ID to execute commands using that user's Terraform credentials. This poses a significant risk as it could lead to unauthorized access and manipulation of infrastructure resources. Organizations utilizing terraform-mcp-server should prioritize upgrading to version 1.1.0 or later to mitigate this vulnerability.

CVE
CVE-2026-16496
Severity
HIGH
CVSS
8.9
EPSS
0.37%

Original NVD Description

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.