hacker-news · Crawled Aug 5, 2026

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

3 CVEs
Read original article ↗

AI Summary

Veeam, HashiCorp, and Django have released patches for critical vulnerabilities in their software. Veeam's Service Provider Console has two critical flaws: CVE-2026-58073 allows unauthenticated attackers to impersonate managed agents and steal credentials (CVSS 9.5), and CVE-2026-58072 enables arbitrary file write leading to remote code execution with low-privilege access (CVSS 9.0). HashiCorp's Terraform MCP Server has a CVSS 10.0 cross-tenant vulnerability (CVE-2026-16498) due to improper session isolation in stateless HTTP mode, allowing token reuse across users. Django patched a high-severity flaw in GeoDjango (CVE-2026-15307) that could allow file writes and potentially remote code execution via spatial lookups accessible to staff users.

AI-extracted · verify before operational use

Extracted Entities 3 found