CVE-2026-16498
CVSS 10 CRITICAL: the terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
Vulnerabilità · 54 giorni fa
Il problema non è un bug qualsiasi. Qui si rompe il confine di fiducia dentro le superfici di amministrazione: un token può finire nella richiesta di un altro tenant, un agent gestito può essere impersonato, un modello GeoDjango visibile allo staff può diventare scrittura su disco e, su alcune configurazioni, code execution.
HashiCorp, Veeam e Django hanno corretto 11 vulnerabilità tra Terraform MCP Server, Veeam Service Provider Console e Django. Le più gravi sono CVE-2026-16498, con riuso cross-tenant del token in Terraform MCP, una falla in Veeam che espone le credenziali di un managed agent, e CVE-2026-15307 in GeoDjango; i fix disponibili sono Terraform MCP Server 1.1.0 o successivo, Veeam Service Provider Console 9.3.0.35057 e Django 6.0.8 o 5.2.17.
Il rischio resta concentrato in configurazioni precise: streamable-HTTP per Terraform MCP, build Veeam 9 precedenti a 9.3, e view permission su modelli GeoDjango con campi spaziali. In questi casi, patchare chiude la falla, ma non annulla il raggio d’azione se un token o le credenziali di un agent sono già stati riusati o esposti.
CVSS 10 CRITICAL: the terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
CVSS 8.8 HIGH: an issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically…
2 fonti che coprono questa storia
Kwetsbaarheden verholpen in Veeam Service Provider Console
Veeam heeft meerdere kwetsbaarheden verholpen in Veeam Service Provider Console.
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and Django patch 11 flaws, including cross-tenant token reuse, agent credential exposure, and possible code execution.
Part of the PlainSec briefing for 2026-08-06