What is CVE-2026-16498?
CVE-2026-16498 is a cross-tenant credential reuse vulnerability in terraform-mcp-server before version 1.1.0, occurring in streamable-HTTP stateless transport mode. It may allow one user's Terraform token to execute tool calls on behalf of subsequent users. Upgrading to version 1.1.0 or later is required to mitigate this issue.
Azərbaycanca: CVE-2026-16498, terraform-mcp-server proqramının 1.1.0-dan əvvəlki versiyalarında streamable-HTTP stateless transport rejimində aşkar edilmiş cross-tenant credential reuse zəifliyidir. Bu, bir istifadəçinin Terraform tokeninin digər istifadəçilər adından tool call icra etməsinə imkan verə bilər. Təhlükəsizlik üçün dərhal 1.1.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
In which software and mode does CVE-2026-16498 occur?
The vulnerability occurs in terraform-mcp-server before version 1.1.0, in streamable-HTTP stateless transport mode.
What should be done to mitigate CVE-2026-16498?
Upgrading to terraform-mcp-server version 1.1.0 or later is required to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.