CVE-2026-47356

7.5

Tenable · Terrascan

Tenable Terrascan versions 0 through 1.18.3 are vulnerable to a Server-Side Request Forgery (SSRF) flaw, allowing unauthenticated attackers to interact with internal network resources.

Executive summary

A critical Server-Side Request Forgery (SSRF) vulnerability in Tenable Terrascan allows unauthenticated remote attackers to potentially access internal services or sensitive metadata.

Vulnerability

This is a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) that occurs due to improper input validation, allowing an unauthenticated remote attacker to force the application to send arbitrary requests to internal or external systems.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high level of risk to organizational infrastructure. Successful exploitation could allow an attacker to bypass firewalls, access internal administrative interfaces, or exfiltrate sensitive cloud metadata, leading to significant unauthorized access or lateral movement within the network.

Remediation

Immediate Action: Upgrade to the latest version of Terrascan to patch the SSRF vulnerability.

Proactive Monitoring: Review application and network egress logs for unusual connection attempts originating from the server hosting Terrascan to internal IP addresses.

Compensating Controls: Implement strict egress filtering on the host machine to prevent the application from making unauthorized outbound connections to internal subnets.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for internal network reconnaissance and service exploitation, organizations using Terrascan should prioritize updating to the latest secure version. Immediate patching is the most effective way to eliminate the risk associated with this SSRF vulnerability.

More Tenable CVEs