PatchSiren cyber security CVE debrief
CVE-2026-33694 Tenable, Inc. CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then. This vulnerability affects Tenable Nessus and Nessus Agent products, allowing an attacker to create a junction and delete arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges. Security teams responsible for these products should review and apply vendor advisories to mitigate this vulnerability. The vulnerability has a CVSS score of 7.4 and a CVSS severity of HIGH. Evidence is limited, and defenders should verify affected product deployments and apply vendor guidance.
- Vendor
- Tenable, Inc.
- Product
- Tenable Nessus, Tenable Nessus Agent
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-08-21
Who should care
Security teams responsible for Tenable Nessus and Nessus Agent products should review and apply vendor advisories to mitigate this vulnerability. This includes teams managing Nessus deployments, security operations centers, and vulnerability management teams. These teams should assess their exposure, apply patches or mitigations, and monitor for potential exploitation attempts.
Technical summary
The vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges. Affected products include Tenable Nessus versions up to 10.11.3 and Nessus Agent versions up to 11.1.2. The vulnerability has a CVSS score of 7.4 and a CVSS severity of HIGH. This condition may allow attackers to execute malicious code with elevated SYSTEM privileges. Tenable Nessus and Nessus Agent products are affected, and security teams should review and apply vendor advisories to mitigate this vulnerability.
Defensive priority
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges.
Recommended defensive actions
- Review and apply vendor advisories for Tenable Nessus and Nessus Agent products
- Inventory and check for vulnerable product versions
- Implement compensating controls to monitor and restrict SYSTEM privilege usage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability affects Tenable Nessus and Nessus Agent products. Vendor advisories are available for mitigation. Evidence is limited, and defenders should verify affected product deployments and apply vendor guidance. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then. Affected products include Tenable Nessus versions up to 10.11.3 and Nessus Agent versions up to 11.1.2.
Official resources
-
CVE-2026-33694 CVE record
CVE.org
-
CVE-2026-33694 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then.