Skip to content

Critical vulnerabilities patched in Veeam, Terraform MCP Server and Django

In brief: HashiCorp, Veeam and Django have patched 11 vulnerabilities, including a cross-tenant flaw in the Terraform MCP Server with a CVSS score of 10.0 and an unauthenticated credential exposure in Veeam with a CVSS score of 9.5.

HashiCorp, Veeam and the Django Software Foundation have fixed a total of 11 security vulnerabilities in Terraform MCP Server, Veeam Service Provider Console and Django. The most severe flaw is a cross-tenant issue with a CVSS score of 10.0.

Three vulnerabilities stand out in the current patch cycle. In HashiCorp’s Terraform MCP Server, a cross-tenant flaw rated at the maximum CVSS score of 10.0 allows a user’s Terraform token to be reused by subsequent users. This affects environments in which multiple tenants share the same MCP server. In Veeam’s Service Provider Console, an unauthenticated vulnerability (CVSS 9.5) allows access to a managed agent’s credentials without an attacker first having to authenticate. According to the original report, no further details are available regarding the individual vulnerabilities among the 11 patched in Django itself.

For CISOs, the combination of a cross-tenant isolation flaw and an unauthenticated credential leak creates an immediate need for action. The Terraform MCP flaw particularly affects organizations that run infrastructure-as-code workflows via shared server instances used by multiple tenants or teams — in the worst case, this risks unauthorized infrastructure changes through token misuse. The Veeam flaw is relevant to managed service provider environments where backup infrastructure is centrally managed via the Service Provider Console; an attacker could gain far-reaching access to customers’ backup systems through the exposed agent credentials.

Operators of the products mentioned should apply the available patches as a priority, particularly in environments with multi-tenant use of the Terraform MCP Server, as well as in MSP scenarios using the Veeam Service Provider Console. Since the original report does not name specific CVE numbers or version details, it is advisable to cross-check the official security advisories from HashiCorp, Veeam and the Django Software Foundation to identify affected versions and available fix releases.


Source: thehackernews.com · Published August 5, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: