Return to Threats

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

thehackernews.com 2026-08-05 AI supply chain Critical

What Happened

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'

Why It Matters

The article reports that HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django/GeoDjango, including a CVSS 10.0 cross-tenant flaw in Terraform MCP and a 9.5 unauthenticated credential-exposure bug in Veeam’s console.[1][2][8][13] These flaws can break tenant isolation and expose managed-agent credentials, directly impacting environments where AI assistants orchestrate infrastructure via Model Context Protocol and Terraform MCP.[1][9][13] From a RealGround perspective, this is an AI supply chain and connector risk: compromised MCP servers or Veeam/Django components could let attackers hijack AI-driven infrastructure workflows, reuse Terraform tokens across tenants, and exfiltrate sensitive data via AI tools.[1][9][13] Organizations using AI agents with Terraform MCP or these services should treat these CVEs as critical in their AI supply chain, enforce rapid patching, harden token scopes, and include MCP and similar connectors in SBOM-driven AI security reviews.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html

Talk to AI CISO