CVE-2026-47356Disclosure(tenable / terrascan)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch tenable terrascan systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form parameter. After scanning the uploaded file, Terrascan sends an HTTP POST request to the attacker-controlled URL containing the full scan results as a JSON body, with the attacker-supplied webhook_token forwarded as a Bearer token in the Authorization header. The retryable HTTP client retries up to 10 times on failure. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • terrascan

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
terrascan

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-19: 2Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 205-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High/Critical - Terrascan Server Mode SSRF & Data Exposure (CVE-2026-47356, CVE-2026-47357, CVE-2026-47358) Terrascan v1.18.3 and prior exposes multiple unauthenticated SSRF vectors in server mode, allowing attackers to submit crafted scan requests or IaC templates that force the server to fetch arbitrary attacker-controlled URLs. In some cases this leads to file:// access, credential exfiltration via ~/.netrc, and leakage of full scan results to attacker endpoints via webhook callbacks. ⚠️ Affected: Terrascan ≤ 1.18.3 (server mode, unauthenticated) ❗ Status: Project archived (no fix will be released) 👉 Impact: • SSRF to internal/external services • Local file read via go-getter / template resolution • Credential leakage via netrc handling • Full scan result exfiltration via webhook_url 👉 Mitigation: • Do NOT expose Terrascan server mode publicly • Restrict to authenticated internal use only or disable server mode entirely • Replace with maintained tooling where possible

    Post summary

    The text announces several high‑severity Terrascan server‑mode SSRF vulnerabilities (CVE‑2026‑47356/57/58), describing their technical effects and providing mitigation guidance, but does not mention a PoC, active exploitation, or a vendor patch.

    00020125
    255 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47356 Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/… https://www.cve.org/CVERecord?id=CVE-2026-47356

    Post summary

    The tweet announces a Server‑Side Request Forgery vulnerability in Terrascan v1.18.3 and earlier, detailing the attack vector and affected endpoint.

    00000111
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptenableterrascan---

Explore more