CVE-2026-2026: Improper Access Control Allows Denial of Service
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2026?
CVE-2026-2026 is classified as a medium severity vulnerability due to its potential to cause Denial of Service.
How do I fix CVE-2026-2026?
To mitigate CVE-2026-2026, ensure that the file permissions in the Nessus Agent directory are properly configured to prevent unauthorized access.
What can attackers do with CVE-2026-2026?
Attackers exploiting CVE-2026-2026 could gain unauthorized access to the Nessus Agent directory, leading to potential Denial of Service attacks.
Which versions of Tenable Nessus Agent are affected by CVE-2026-2026?
CVE-2026-2026 affects all versions of the Tenable Nessus Agent that have weak file permissions.
What is the impact of CVE-2026-2026 on Windows hosts?
On Windows hosts, CVE-2026-2026 can lead to unauthorized access and may result in service disruptions due to Denial of Service vulnerabilities.