cbcvebase.
CVE-2026-14869
published 2026-07-28

CVE-2026-14869: The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an…

PriorityP259high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.38%
30.9th percentile
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.

Affected

1 ranges
VendorProductVersion rangeFixed in
hashicorptooling>= 0.3.0 < 1.1.01.1.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.