A critical vulnerability, CVE-2026-16498, has been identified in terraform-mcp-server versions before 1.1.0. The flaw resides in the streamable-HTTP stateless transport mode, where improper handling of Terraform authentication tokens enables cross-tenant credential reuse. Attackers could exploit this to execute unauthorized tool calls on behalf of other users, potentially leading to privilege escalation, data breaches, or service disruption. The vulnerability affects all deployments utilizing the vulnerable version of terraform-mcp-server and Terraform platforms relying on its stateless transport mode. With a CVSS score of 10.0, this issue is classified as critical due to its potential for remote code execution and lateral movement within compromised environments. Immediate mitigation requires upgrading to terraform-mcp-server 1.1.0 or later, where the issue has been resolved through enhanced token isolation mechanisms. Organizations are advised to audit their Terraform configurations, enforce strict access controls, and monitor for anomalous API activity until the update is applied. No workarounds are available for versions prior to 1.1.0.
CRITICAL
CVSS 10.0
CVE-2026-16498
2026-08-14
Critical Cross-Tenant Credential Reuse Vulnerability in Terraform-MCP-Server (CVE-2026-16498)
A critical cross-tenant credential reuse vulnerability in terraform-mcp-server versions prior to 1.1.0 allows unauthorized execution of tool calls via reused Terraform tokens. This high-severity issue is resolved in version 1.1.0.