CVE-2026-47357Disclosure(tenable / terrascan)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch tenable terrascan systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-getter (v1.7.5) without validation. Go-getter's HttpGetter supports the X-Terraform-Get response header, allowing the attacker's server to redirect the download to a file:// URL, enabling local file read. Additionally, HttpGetter has Netrc set to true, causing it to read ~/.netrc and send stored credentials to attacker-controlled hostnames. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-610CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • terrascan

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
terrascan

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-19: 2Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 205-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High/Critical - Terrascan Server Mode SSRF & Data Exposure (CVE-2026-47356, CVE-2026-47357, CVE-2026-47358) Terrascan v1.18.3 and prior exposes multiple unauthenticated SSRF vectors in server mode, allowing attackers to submit crafted scan requests or IaC templates that force the server to fetch arbitrary attacker-controlled URLs. In some cases this leads to file:// access, credential exfiltration via ~/.netrc, and leakage of full scan results to attacker endpoints via webhook callbacks. ⚠️ Affected: Terrascan ≤ 1.18.3 (server mode, unauthenticated) ❗ Status: Project archived (no fix will be released) 👉 Impact: • SSRF to internal/external services • Local file read via go-getter / template resolution • Credential leakage via netrc handling • Full scan result exfiltration via webhook_url 👉 Mitigation: • Do NOT expose Terrascan server mode publicly • Restrict to authenticated internal use only or disable server mode entirely • Replace with maintained tooling where possible

    Post summary

    The post announces newly disclosed SSRF vulnerabilities in Terrascan up to v1.18.3, details the attack surface, and offers mitigation recommendations while noting no patch is available.

    00020125
    255 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47357 Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{i… https://www.cve.org/CVERecord?id=CVE-2026-47357

    Post summary

    A Server‑Side Request Forgery vulnerability (CVE‑2026‑47357) is disclosed for Terrascan v1.18.3 and earlier, affecting the remote directory scan endpoint via remote_url. No exploit, patch, or active exploitation details are provided.

    00000110
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptenableterrascan---

Explore more