CVE-2026-82477
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
- Published Aug 29, 2026
- CVSS 5.8 medium
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available