Vulnary
← back to the feed
Critical· 9.2

CVE-2026-47358

Terrascan versions 1.18.3 and earlier are vulnerable to a Server‑Side Request Forgery (SSRF) flaw when running in server mode. An unauthenticated attacker can upload an infrastructure‑as‑code template that points to an attacker‑controlled URL, causing Terrascan to fetch that URL on the server. The fetched content can be a remote file or a local file via a file:// URL, potentially exposing sensitive data or allowing code execution.

publishedMay 19, 2026
last modifiedJul 24, 2026
sourcesNVD
severity · cvss
9.2
critical · how bad it is
exploitation · epss
<1%
39th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 7, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Tenable Terrascan v1.18.3 and earlier, when deployed in server mode (listening on 0.0.0.0 with no authentication).

02

Real-world impact

An attacker can make the Terrascan server retrieve arbitrary files or URLs, which may expose confidential data, read local files, or execute malicious code on the host running Terrascan.

03

Why this severity

The CVSS score of 9.2 reflects the high impact of the vulnerability: it allows an attacker to read or write files on the server, has no authentication or user interaction required, and can be exploited remotely with low effort.

04

What to do about it

no official fix yet
interim mitigations
  • Avoid running Terrascan in server mode; use the local scanner instead.
  • If server mode is required, restrict network access to the Terrascan server so only trusted hosts can connect.
  • Consider disabling the ability to upload IaC templates or validate template URLs before processing.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

NVD description indicates no patch will be released.

05

Timeline

  1. May 19, 2026 · May 19, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 24, 2026 · 11d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-47358: Terrascan versions 1.18.3 and earlier are vulnerable to a Server‑Side · Vulnary