CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3914

As cited

Copy frozen at (site build).

vulnerabilities

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation patched 11 vulnerabilities across their products. The most critical issues include an unauthenticated credential disclosure flaw in Veeam Service Provider Console (CVSS 9.5) and a cross-tenant token reuse vulnerability in Terraform MCP Server (CVSS 10.0) that allows one user's credentials to be leveraged by subsequent users.

Why it matters: Organizations running Veeam backup infrastructure or Terraform MCP deployments face immediate exposure to credential theft and privilege escalation; patch these products and rotate any potentially exposed tokens and managed agent credentials now.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation patched 11 vulnerabilities across their products. The most critical issues include an unauthenticated credential disclosure flaw in Veeam Service Provider Console (CVSS 9.5) and a cross-tenant token reuse vulnerability in Terraform MCP Server (CVSS 10.0) that allows one user's credentials to be leveraged by subsequent users.

Why it matters: Organizations running Veeam backup infrastructure or Terraform MCP deployments face immediate exposure to credential theft and privilege escalation; patch these products and rotate any potentially exposed tokens and managed agent credentials now.

VendorsVeeam
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary