CVE-2026-82477EPSS p38.9%
CVE-2026-82477CVE-2026-82477
Description
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
Scoring
| CVSS | 5.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
| EPSS | 0.47% probability of exploitation · percentile 38.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-01 |