Operator Trust Opens Tenable Sensor Proxy to Code Execution

The sensor is only safe if the person connecting it can trust the host on the other end. In Tenable Sensor Proxy, that trust decision can be turned against the operator: an attacker can get elevated code execution by getting the sensor connected to a host they control. The flaw is CVE-2026-18667. It affects Sensor Proxy 1.4.1 and earlier, and Tenable says version 1.4.2 fixes it. The risky part is not simple network exposure. It is the operator-initiated connection to an external host, which means environments that manually connect sensors outside the trust boundary carry the most direct exposure.

Part of the PlainSec briefing for 2026-08-04

Editions

Sources