CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-16496: Stateful Mode Session Isolation Failure in Terraform MCP Server

August 5, 2026

CVE-2026-16496 (CVSS 8.9) is a stateful-mode session isolation flaw in Terraform MCP Server. The credential cache uses the MCP session ID as the sole lookup key, allowing a user who obtains another user's session ID to run tool calls with that user's Terraform client and access resources permitted by the victim's token. Fixed in version 1.1.0.