CVE-2026-47358
Terrascan versions 1.18.3 and earlier are vulnerable to a Server‑Side Request Forgery (SSRF) flaw when running in server mode. An unauthenticated attacker can upload an infrastructure‑as‑code template that points to an attacker‑controlled URL, causing Terrascan to fetch that URL on the server. The fetched content can be a remote file or a local file via a file:// URL, potentially exposing sensitive data or allowing code execution.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Tenable Terrascan v1.18.3 and earlier, when deployed in server mode (listening on 0.0.0.0 with no authentication).
Real-world impact
An attacker can make the Terrascan server retrieve arbitrary files or URLs, which may expose confidential data, read local files, or execute malicious code on the host running Terrascan.
Why this severity
The CVSS score of 9.2 reflects the high impact of the vulnerability: it allows an attacker to read or write files on the server, has no authentication or user interaction required, and can be exploited remotely with low effort.
What to do about it
- ›Avoid running Terrascan in server mode; use the local scanner instead.
- ›If server mode is required, restrict network access to the Terrascan server so only trusted hosts can connect.
- ›Consider disabling the ability to upload IaC templates or validate template URLs before processing.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description indicates no patch will be released.
Timeline
- May 19, 2026 · May 19, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/tenable/terrascanproduct