{"id":"CVE-2025-13432","title":"Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace","summary":"Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user wi…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-863"],"vendor":"hashicorp","product":"terraform","affected":["terraform >= 1.0.0, < 1.0.3","terraform = 1.1.0"],"patched":["terraform 1.0.3"],"published":"2025-11-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13432","references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2025-34-terraform-enterprise-state-versions-can-be-created-by-users-without-sufficient-write-access/76821","label":"security@hashicorp.com"}],"tags":["nvd"],"epss":0.00181,"epssPercentile":0.07006,"ingestedAt":"2026-10-08T10:28:20.228Z","slug":"CVE-2025-13432","body":"## Overview\n\nTerraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.\n\n## Affected\n\n- `terraform >= 1.0.0, < 1.0.3`\n- `terraform = 1.1.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `terraform 1.0.3`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}