Scanner Flaws Expose Files and Privileges on Windows

Two security products broke in ways that matter to defenders, not just their vendors. One flaw lets a remote attacker read files off a LogScale server. The other turns a Windows scanner component into a local privilege-escalation path that can delete arbitrary files and may reach elevated code execution. CrowdStrike fixed CVE-2026-40050, a critical unauthenticated path traversal in LogScale. It affects self-hosted LogScale customers; LogScale SaaS was mitigated and Next-Gen SIEM customers are not affected. Tenable fixed CVE-2026-33694 in Nessus on Windows and issued separate advisories for Nessus and Nessus Agent. The flaw uses junctions to delete arbitrary files with System privileges, and exploitation could also lead to arbitrary code execution with elevated privileges. The pattern matters more than the individual bugs. Security tooling that runs with broad access can become a privilege-escalation target on Windows, and a server-side path traversal in a logging platform can expose sensitive files even without full system compromise.

Part of the PlainSec briefing for 2026-04-25

Sources