PatchSiren cyber security CVE debrief
CVE-2026-33694 Tenable, Inc. CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then. This vulnerability affects Tenable Nessus and Nessus Agent products, allowing an attacker to create a junction and delete arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges. Security teams responsible for these products should review and apply vendor advisories to mitigate this vulnerability. The vulnerability has a CVSS score of 7.4 and a CVSS severity of HIGH. Evidence is limited, and defenders should verify affected product deployments and apply vendor guidance.
- Vendor
- Tenable, Inc.
- Product
- Tenable Nessus, Tenable Nessus Agent
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-08-21
Who should care
Security teams responsible for Tenable Nessus and Nessus Agent products should review and apply vendor advisories to mitigate this vulnerability. This includes teams managing Nessus deployments, security operations centers, and vulnerability management teams. These teams should assess their exposure, apply patches or mitigations, and monitor for potential exploitation attempts.
Technical summary
The vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges. Affected products include Tenable Nessus versions up to 10.11.3 and Nessus Agent versions up to 11.1.2. The vulnerability has a CVSS score of 7.4 and a CVSS severity of HIGH. This condition may allow attackers to execute malicious code with elevated SYSTEM privileges. Tenable Nessus and Nessus Agent products are affected, and security teams should review and apply vendor advisories to mitigate this vulnerability.
Defensive priority
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges.
Recommended defensive actions
- Review and apply vendor advisories for Tenable Nessus and Nessus Agent products
- Inventory and check for vulnerable product versions
- Implement compensating controls to monitor and restrict SYSTEM privilege usage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability affects Tenable Nessus and Nessus Agent products. Vendor advisories are available for mitigation. Evidence is limited, and defenders should verify affected product deployments and apply vendor guidance. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then. Affected products include Tenable Nessus versions up to 10.11.3 and Nessus Agent versions up to 11.1.2.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-33694 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-33694
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-33694 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33694
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tenable.com/security/tns-2026-12
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tenable.com/security/tns-2026-13
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.