Skip to content
HashiCorpCVE-2026-16496

HashiCorp Tooling: session fixation

High8.9CVE-2026-16496 · Published Jul 28, 2026 · updated Jul 30, 2026

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Tooling
Product
>= 0.3.0, < 1.1.01.1.0
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Consul: denial of service
Medium5.3Aug 7
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are...
Medium4.2Aug 7
HashiCorp Tooling: server-side request forgery
High8.6Jul 29
In consul-mcp-server
Critical10.0Jul 29
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant...
Critical10.0Jul 28
HashiCorp Tooling: server-side request forgery
High8.6Jul 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.