Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-16498
CVE
CVE-2026-16498
View on NVD ↗
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Source Articles
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Veeam, HashiCorp, and Django have released patches for critical vulnerabilities in their software. Veeam's Service Provider Console has two critical flaws: CVE-2026-58073 allows unauthenticated attackers to impersonate managed agents and steal credentials (CVSS 9.5), and CVE-2026-58072 enables arbitrary file write leading to remote code execution with low-privilege access (CVSS 9.0). HashiCorp's Terraform MCP Server has a CVSS 10.0 cross-tenant vulnerability (CVE-2026-16498) due to improper session isolation in stateless HTTP mode, allowing token reuse across users. Django patched a high-severity flaw in GeoDjango (CVE-2026-15307) that could allow file writes and potentially remote code execution via spatial lookups accessible to staff users.
hacker-news
Aug 5, 2026