CVE-2026-47358Disclosure(tenable / terrascan)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch tenable terrascan systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticated remote attacker can upload an ARM template containing a templateLink.uri or parametersLink.uri field, or a CloudFormation template containing an AWS::CloudFormation::Stack TemplateURL field, pointing to an attacker-controlled URL. Terrascan will fetch the attacker-controlled URL server-side. Unlike SSRF via the remote scan endpoint, file:// URLs are directly usable without requiring an X-Terraform-Get redirect, enabling local file read. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-610CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • terrascan

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
terrascan

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-19: 2Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 205-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High/Critical - Terrascan Server Mode SSRF & Data Exposure (CVE-2026-47356, CVE-2026-47357, CVE-2026-47358) Terrascan v1.18.3 and prior exposes multiple unauthenticated SSRF vectors in server mode, allowing attackers to submit crafted scan requests or IaC templates that force the server to fetch arbitrary attacker-controlled URLs. In some cases this leads to file:// access, credential exfiltration via ~/.netrc, and leakage of full scan results to attacker endpoints via webhook callbacks. ⚠️ Affected: Terrascan ≤ 1.18.3 (server mode, unauthenticated) ❗ Status: Project archived (no fix will be released) 👉 Impact: • SSRF to internal/external services • Local file read via go-getter / template resolution • Credential leakage via netrc handling • Full scan result exfiltration via webhook_url 👉 Mitigation: • Do NOT expose Terrascan server mode publicly • Restrict to authenticated internal use only or disable server mode entirely • Replace with maintained tooling where possible

    Post summary

    The post announces CVE‑2026‑47356, 47357, and 47358 as high‑critical SSRF and data exposure flaws in Terrascan, provides detailed technical description and mitigation advice, but no PoC, exploit code, or evidence of active exploitation.

    00020125
    255 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47358 Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. Wh… https://www.cve.org/CVERecord?id=CVE-2026-47358

    Post summary

    The new SSRF vulnerability CVE-2026-47358 in Terrascan v1.18.3 and earlier versions has been publicly disclosed, allowing attackers to resolve external URLs in uploaded IaC templates when running in server mode.

    00000109
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptenableterrascan---

Explore more