SSRF Vulnerability in MITRE SAF Heimdall Affects Network Security
CVE-2026-82477

5.8MEDIUM

Key Information:

Vendor

Mitre

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82477?

In versions 2.11.6 through 2.13.x prior to 2.14.0 of MITRE SAF Heimdall, a Server-Side Request Forgery (SSRF) vulnerability is present, allowing remote attackers to exploit the Tenable proxy endpoint and gain unauthorized access to internal network resources. This flaw arises in the backend code located in apps/backend/src/tenable/tenable.controller.ts, highlighting the need for prompt updates to mitigate potential security risks.

Affected Version(s)

Heimdall 2.11.6 < 2.14.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.