HashiCorp Terraform Enterprise State Version Manipulation Vulnerability

Vulnerability

A vulnerability exists in Terraform Enterprise versions prior to 1.1.1 and 1.0.2, allowing users with limited permissions to create new Terraform state versions in a workspace. This could lead to unauthorized changes in infrastructure if the new state version is applied, either automatically or with approval from a user who has the necessary permissions. The issue arises from a combination of workspace and organizational permissions that, when held by a user, enable them to overwrite state versions without proper write access.

Impact

Exploitation of this vulnerability could result in unauthorized modifications to infrastructure managed by Terraform, potentially leading to disruptions or misconfigurations.

Remediation

Users are advised to upgrade to Terraform Enterprise versions 1.1.1 or 1.0.3.

Added: Nov 21, 2025, 4:38 PM
Updated: Nov 21, 2025, 4:38 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.