Multiple critical vulnerabilities in the HashiCorp Terraform MCP Server allow an unauthenticated remote attacker to bypass security controls, disclose sensitive information, and manipulate data. The CVSS Base Score for these vulnerabilities is a maximum of 10.0. Affected versions are all releases prior to version 1.1.0, and a mitigation is available.
[WID-SEC-2026-2572] Hashicorp Terraform MCP Server: Mehrere Schwachstellen CVSS Base Score 10.0 (kritisch) CVSS Temporal Score 8.7 (hoch) Remoteangriff ja Datum 28.07.2026 Stand 29.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Terraform ist ein Infrastruktur-als-Code-Tool. Produkte 28.07.2026 Hashicorp Terraform mcp-server <1.1.0 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Hashicorp Terraform MCP Server ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und Daten zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben