CVE-2026-18667

Tenable · Sensor Proxy

Tenable Sensor Proxy is vulnerable to remote code execution, allowing an unauthenticated attacker to gain elevated privileges if an operator connects the sensor to a malicious host.

Executive summary

A critical remote code execution vulnerability in Tenable Sensor Proxy permits attackers to gain elevated privileges through operator-assisted connection to malicious hosts.

Vulnerability

This is a remote code execution vulnerability (CWE-94) that allows an unauthenticated attacker to execute code with elevated privileges. The attack vector relies on social engineering or deception, where an operator is induced to connect the sensor to an attacker-controlled host.

Business impact

With a CVSS score of 9.6, this vulnerability represents a high-impact risk to organizational security infrastructure. Successful exploitation allows attackers to gain full administrative control over the sensor proxy, potentially facilitating lateral movement and unauthorized access to sensitive security telemetry.

Remediation

Immediate Action: Update Tenable Sensor Proxy to version 1.4.2 immediately by downloading the installer from the official Tenable Downloads Portal.

Proactive Monitoring: Audit sensor configuration logs and connection endpoints to ensure sensors are only communicating with verified and trusted Tenable infrastructure.

Compensating Controls: Implement strict egress filtering on the network to prevent the sensor from establishing unauthorized connections to external or untrusted hosts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Tenable Sensor Proxy must prioritize the upgrade to version 1.4.2. Additionally, educate security personnel on the risks associated with connecting security appliances to untrusted or unverified network endpoints to prevent the exploitation of this vector.