CVE-2026-82477: SSRF
Published Aug 29, 2026
·Updated
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
Affected Software
1 affected component
MITRE SAF Heimdall>=2.11.6<2.14.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MITRE SAF Heimdallto a version that resolves this vulnerability.Fixed in 2.14.0
Event History
Aug 29, 2026
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Heimdall versions are affected, and what version fixes the issue?
MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0 are affected. Upgrade to version 2.14.0 or later.
2
Does an attacker need credentials or user interaction to exploit this issue?
No. The vulnerability is remotely exploitable without privileges or user interaction.
3
What could an attacker access through a successful exploit?
An attacker can use the Tenable proxy endpoint to access internal network resources reachable by the affected Heimdall deployment.