What is CVE-2026-16496?
The terraform-mcp-server before version 1.1.0 contains an authorization bypass in streamable-HTTP stateful transport mode. A user who obtains another user's MCP session ID can execute tool calls using that user's Terraform credentials, leading to potential unauthorized actions. Immediate upgrade to version 1.1.0 is strongly recommended.
Azərbaycanca: terraform-mcp-server 1.1.0-dan əvvəlki versiyalarda streamable-HTTP stateful transport rejimində authorization bypass zəifliyi aşkarlanıb. Başqa bir istifadəçinin MCP session ID-sini ələ keçirən şəxs, həmin istifadəçinin Terraform etimadnamələri ilə tool call-ları icra edə bilər. Dərhal 1.1.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What security vulnerability exists in terraform-mcp-server versions before 1.1.0 when using streamable-HTTP stateful transport mode?
An authorization bypass vulnerability allows a user who obtains another user's MCP session ID to execute tool calls using that user's Terraform credentials, potentially leading to unauthorized actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.