CVE-2026-16496
Description
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.
Summary dbcve.org
The terraform-mcp-server before version 1.1.0 has an authorization bypass in its streamable-HTTP stateful transport mode. An attacker who obtains another user's MCP session ID can execute tool calls using the victim's Terraform credentials, effectively hijacking the session and performing actions with the victim's cloud infrastructure access.
Mitigation
Upgrade terraform-mcp-server to version 1.1.0 or later to remediate this session hijacking vulnerability.