A vulnerability has been found in HashiCorp terraform-mcp-server up to 1.0.9 and classified as critical. This impacts an unknown function of the component Streamable-HTTP Stateful Transport Mode. This manipulation causes authorization bypass.

This vulnerability appears as CVE-2026-16496. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.