Vulnerability Description
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/mitre/heimdall2/commit/b6a9cdb4fc01f96aaa1a77cc27d1d449b48593
- https://github.com/mitre/heimdall2/releases/tag/v2.14.0
- https://github.com/mitre/heimdall2/security/advisories/GHSA-g9vx-2rpf-gpch
- https://github.com/mitre/heimdall2/security/advisories/GHSA-g9vx-2rpf-gpch
FAQ
What is CVE-2026-82477?
CVE-2026-82477 is a vulnerability with a CVSS score of 5.8 (MEDIUM). In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/te...
How severe is CVE-2026-82477?
CVE-2026-82477 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82477?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.