CVE-2026-16498
CVSS 10 CRITICAL: the terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
Vulnerabilities · 54 days ago
These flaws break the trust boundary in the management layer. A tenant request can inherit the wrong Terraform token, a console can hand out a managed agent’s credentials, and a GeoDjango lookup can turn staff access into file write or code execution on some setups.
HashiCorp fixed CVE-2026-16498 in Terraform MCP Server 1.1.0 or later. It affects streamable-HTTP deployments, where one user’s token can be reused in later users’ requests. Veeam fixed the credential-exposure bug in Service Provider Console 9.3.0.35057, and Django fixed CVE-2026-15307 in 6.0.8 and 5.2.17 for GeoDjango admin views tied to models with spatial fields.
The shared problem is not just a bad request. It is a control plane that can start acting as the wrong principal. If a tenant token, agent credential, or staff session was already exposed, patching closes the flaw but does not erase the access it already handed out.
CVSS 10 CRITICAL: the terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
CVSS 8.8 HIGH: an issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically…
2 sources covering this story
Kwetsbaarheden verholpen in Veeam Service Provider Console
Veeam heeft meerdere kwetsbaarheden verholpen in Veeam Service Provider Console.
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and Django patch 11 flaws, including cross-tenant token reuse, agent credential exposure, and possible code execution.
Part of the PlainSec briefing for 2026-08-06