CVE-2025-13432EPSS p7.0%
CVE-2025-13432CVE-2025-13432
hashicorp / terraform
Description
Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 0.18% probability of exploitation · percentile 7.0% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |