CVE-2026-18667
CVSS 9.6 CRITICAL: a vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing…
Vulnerabilities · 55 days ago
The sensor is only safe if the person connecting it can trust the host on the other end. In Tenable Sensor Proxy, that trust decision can be turned against the operator: an attacker can get elevated code execution by getting the sensor connected to a host they control.
The flaw is CVE-2026-18667. It affects Sensor Proxy 1.4.1 and earlier, and Tenable says version 1.4.2 fixes it.
The risky part is not simple network exposure. It is the operator-initiated connection to an external host, which means environments that manually connect sensors outside the trust boundary carry the most direct exposure.
CVSS 9.6 CRITICAL: a vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing…
2 sources covering this story
Vulnerabilità in Tenable Sensor Proxy
Risolta una vulnerabilità con gravità “critica” in Tenable Sensor Proxy.
Inyección de código en Sensor Proxy de Tenable
Neil Graves, de LVL 0x00, LLC ha informado a Tenable de una vulnerabilidad crítica que podría permitir
Part of the PlainSec briefing for 2026-08-05