Vulnerability  ·  2026-07-30

HashiCorp Terraform MCP Server — Cross-Tenant Credential Reuse in Stateless HTTP Mode (Critical)

VulnerabilityHigh impactGlobalCVE-2026-16498
HashiCorp disclosed (2026-07-28) that terraform-mcp-server before 1.1.0 fails to properly isolate per-request identity in streamable-HTTP stateless mode, allowing one user's Terraform token to be reused for another user's tool calls. This is one of three related vulnerabilities (CVE-2026-16498, CVE-2026-16496, CVE-2026-14869) disclosed in the same bulletin.
MCP servers are increasingly deployed as shared multi-tenant AI-agent gateways to infrastructure tooling; a credential-reuse flaw in a widely-used official MCP server for Terraform means an AI agent acting on behalf of one tenant could silently execute privileged infrastructure operations using another tenant's credentials — a direct blast-radius amplifier for agentic DevOps pipelines.
In streamable-HTTP stateless transport mode, one user's Terraform API token can be reused to execute tool calls on behalf of a subsequent, different user — allowing cross-tenant credential theft/reuse without direct exploitation steps beyond normal API use of a shared stateless endpoint.
hashicorp/terraform-mcp-server 0.2.1 up to and including 1.0.0
Upgrade to terraform-mcp-server 1.1.0. See HashiCorp Security Bulletin HCSEC-2026-23.
HashiCorp Security Bulletin HCSEC-2026-23NVD CVE-2026-16498HashiCorp Security Bulletin HCSEC-2026-24
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →