CVE-2026-14869
published 2026-07-28CVE-2026-14869: The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an…
PriorityP259high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.38%
30.9th percentile
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hashicorp | tooling | >= 0.3.0 < 1.1.0 | 1.1.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HashiCorp terraform-mcp-server up to 1.0.x Streamable-HTTP Transport server-side request forgery
vuldb·2026-07-28·CVSS 8.6
CVE-2026-14869 [HIGH] HashiCorp terraform-mcp-server up to 1.0.x Streamable-HTTP Transport server-side request forgery
A vulnerability was found in HashiCorp terraform-mcp-server up to 1.0.x. It has been rated as critical. This affects an unknown part of the component Streamable-HTTP Transport. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-14869. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the serv
ghsa_unreviewed·2026-07-28·CVSS 8.6
CVE-2026-14869 [HIGH] CWE-918 The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the serv
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
blogs_hackernews·2026-08-10
CVE-2026-34348 ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.
That’s only part of it. Here’s everything else that made the Monday recap.
## ⚡ Threat of the Week
Anthropic's Model Attempts to Poison Open-Source Project — A new evaluati
Hackernews
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
blogs_hackernews·2026-08-05·CVSS 9.5
CVE-2026-58073 [CRITICAL] Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.
The three most serious:
An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5
A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users' requests, scored a maximum 10.0 on its CVE record
A flaw in GeoDjango's spatial lookups that can write a file to disk and, on some setups, run code, rea
2026-07-28
Published