CVE-2026-82477
Received Received - Intake

SSRF Vulnerability in MITRE SAF Heimdall via Tenable Proxy Endpoint

Vulnerability report for CVE-2026-82477, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: MITRE

Description

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mitre heimdall From 2.11.6 (inc) to 2.14.0 (exc)
mitre heimdall From 2.13.0 (inc) to 2.14.0 (exc)
mitre heimdall 2.14.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in MITRE SAF Heimdall versions 2.11.6 through 2.13.x before 2.14.0. It allows remote attackers to access internal network resources by exploiting the Tenable proxy endpoint in the application.

Detection Guidance

To detect this SSRF vulnerability in Heimdall 2.11.6 through 2.13.x, monitor network traffic for unauthorized internal requests originating from the Tenable proxy endpoint. Check logs for attempts to access internal hosts via the host_url parameter. Verify if host URLs lack proper protocol validation or contain allowlisted domains.

Impact Analysis

An attacker could use this flaw to access internal systems or sensitive data within your network by sending crafted requests through the vulnerable Tenable proxy endpoint. This could lead to unauthorized information disclosure or network reconnaissance.

Compliance Impact

This SSRF vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Compliance may be impacted if unauthorized access occurs.

Mitigation Strategies

Upgrade Heimdall to version 2.14.0 or later to address the SSRF vulnerability in the Tenable integration. Ensure Tenable host URLs are validated against an allowlist and require explicit authentication. Check environment variables for Tenable host URLs to confirm they use the consolidated single variable format.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82477. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart