The Architectural Failure Behind the MCP Session Isolation Crisis
The disclosure of CVE-2026-16498, a CVSS 10.0 vulnerability in the Terraform MCP Server, highlights a critical instability within current agent infrastructure. The flaw, which allowed for cross-tenant credential reuse in streamable-HTTP stateless transport mode, originated from a failure to generate unique session identifiers. Because the server’s credential cache relied on these non-unique IDs, one user’s…