Weak file permissions in Tenable Nessus Agent may enable local denial of service

What is CVE-2026-2026?

CVE-2026-2026 is a vulnerability classified as Incorrect Default Permissions, affecting Agent (affected versions: 11.1.0 – < 11.1.2 and < 11.0.4). This vulnerability is rated Medium, with a CVSS score of 5.4. Current sources do not report this vulnerability as exploited.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.

Affected products and scope

Tenable Nessus Agent 11.1.0 through 11.1.1: affected; Tenable released 11.1.2 as the fixed release. • Tenable Nessus Agent 11.0.3 and earlier: affected; Tenable released 11.0.4 as the fixed release. • The supported scope is Nessus Agent on Windows hosts. The status of products, platforms, or branches not listed in the supplied data is not established.

Technical details

On Windows hosts, the vulnerable condition is weak access control on the Nessus Agent directory. These permissions may allow an unauthorized local principal to access files that should be more restricted. Tenable and the vulnerability record link this condition to potential DoS, but do not identify the exact file, ACL entry, or operation that causes the denial of service. The supplied attack characteristics indicate that exploitation requires local access with low privileges, has low complexity, and needs no user interaction. The record indicates limited confidentiality impact and high availability impact, with no integrity impact; it does not describe privilege escalation.

Exploitability

The vulnerability is locally reachable on a Windows host and is not described as remotely exploitable over the network. An attacker needs low privileges, does not need user interaction, and faces low attack complexity. The supplied record does not confirm active exploitation. No public exploit is identified in the record, and Tenable's detection plugin states that no known exploits are available.

Technical impact

The vulnerability may allow a low-privilege local user to obtain unauthorized access to files in the Nessus Agent directory. The primary technical outcome is potential DoS or loss of agent availability. This may prevent an endpoint from performing or reporting vulnerability-assessment activity as expected. The record indicates limited confidentiality impact and no integrity impact; it does not confirm code execution, privilege escalation, or full host control.

Business impact

• A low-privilege local account may access files in the Nessus Agent directory beyond the intended authorization boundary. • Abuse of this condition may reduce or interrupt agent availability on an affected Windows host. • If the agent stops functioning or stops reporting, the organization may lose part of its endpoint monitoring and vulnerability-assessment coverage. • The record indicates that availability is the main concern, with limited potential confidentiality impact. It provides no evidence of integrity modification or full host compromise.

Remediation

  1. Upgrade installations in the 11.1.x branch to Nessus Agent 11.1.2.
  2. Upgrade affected installations in the 11.0.x branch to Nessus Agent 11.0.4.
  3. Obtain the installation files from the Tenable Downloads Portal, then verify that the agent is running the intended fixed release and continues to report normally.
  4. If an upgrade cannot be completed immediately, review the NTFS permissions on the Nessus Agent directory and restrict access according to vendor-supported configuration. The public source does not provide a specific mitigation ACL, so do not apply an assumed permission template.

Detection

• Inventory Windows hosts running Nessus Agent and compare deployed releases with the affected branches. • Tenable plugin 298991 can assist with inventory-based detection. The plugin relies on the application's self-reported version and does not directly test the file-permission condition. • Review the NTFS permissions on the Nessus Agent installation directory, looking for read, write, or modify access broader than the intended policy. This is a precautionary check because the public source does not define the expected ACL in detail. • Monitor agent service health and loss of agent reporting. Treat these as precautionary monitoring signals, not as confirmed indicators for this vulnerability. • Do not treat the absence of unusual log activity as proof that a host is unaffected.

Sources (7)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard