CVE-2026-18667 PUBLISHED

Sensor Proxy Version 1.4.2 Fixes One Vulnerability

Assigner: tenable
Reserved: 03.08.2026 Published: 03.08.2026 Updated: 03.08.2026

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Tenable, Inc.
Product Sensor Proxy
Versions Default: affected
  • affected from 0 to 1.4.2 (excl.)

Solutions

Tenable has released Sensor Proxy 1.4.2 to address these issues. The installation files can only be obtained via the Tenable Downloads Portal ( https://www.tenable.com/downloads/sensor-proxy ).

Credits

  • Neil Graves / LVL 0x00, LLC finder

References

Problem Types

  • CWE-94 CWE