HIGH🇵🇱 Wersja polska

CVE-2026-47356

CVSS 8.7v4.0pub. 2026-05-19upd. 2026-07-24

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form parameter. After scanning the uploaded file, Terrascan sends an HTTP POST request to the attacker-controlled URL containing the full scan results as a JSON body, with the attacker-supplied webhook_token forwarded as a Bearer token in the Authorization header. The retryable HTTP client retries up to 10 times on failure. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tenable Terrascan

    APP
    Tenable
    ≤ 1.18.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2026-47357CRITICAL9.2PL ✓same product

SSRF w Tenable Terrascan — odczyt plików lokalnych i kradzież danych uwierzytelniających

CVE-2026-47358CRITICAL9.2PL ✓same product

SSRF z możliwością odczytu plików lokalnych w Tenable Terrascan

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same vendor

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2026-64877CRITICAL9.4PL ✓same vendor

SQL injection w REST API ticketingu — dostęp do danych bazy

CVE-2026-64878CRITICAL9.4PL ✓same vendor

Command Injection w endpoint Analysis REST — RCE przez parametry filtrów