Summary
Tenable Nessus and Nessus Agent on Windows contain a local vulnerability in the file-handling path used by the service. A low-privileged authenticated user can create a junction that is followed by a SYSTEM-level file operation, which can delete arbitrary files and be chained into SYSTEM code execution. Tenable rates user interaction as required, and this is not a network attack.
Why Planned Fix?
3/6Exploitation Details
Execute arbitrary code as SYSTEM on the Windows host.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Nessus | 10.11.3 and earlier |
| Nessus Agent | 11.1.2 and earlier |
Tenable Nessus is a vulnerability scanner used to assess hosts and networks for security weaknesses. Nessus Agent is its Windows endpoint agent for collecting local assessment data from managed machines.
Affected ComponentWindows junction-handling file deletion path in the Nessus and Nessus Agent services.
Windows junction-handling file deletion path in the Nessus and Nessus Agent services.
Not available
Not available
Probability of exploitation in the next 30 days
Worse than 3% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
Sources
| Source | Article |
|---|---|
| www.tenable.com | [R1] Nessus Agent Version 11.1.3 Fixes Arbitrary File Deletion |
| www.tenable.com | [R1] Nessus Versions 10.11.4 and 10.12.0 Fixes Arbitrary File Deletion |
| www.tenable.com | CVE-2026-33694 |
| www.tenable.com | Tenable Nessus Agent < 11.1.3 Arbitrary File Deletion (TNS-2026-12) |
| www.cert.ssi.gouv.fr | Vulnérabilité dans les produits Tenable |
Priority History
Initial analysis